CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2018-07-24T13:00:00
Updated: 2024-08-05T07:54:36.246Z
Reserved: 2018-05-09T00:00:00
Link: CVE-2018-10905
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-24T13:29:00.447
Modified: 2024-11-21T03:42:16.323
Link: CVE-2018-10905
Redhat