{"id":"RHSA-2018:2745","summary":"Red Hat Security Advisory: CloudForms 4.5.5 security, bug fix and enhancement update","modified":"2026-07-01T10:04:35Z","published":"2024-09-16T01:40:20Z","upstream":["CVE-2018-10905","CVE-2018-3760"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2745"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"ARTICLE","url":"https://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.5/html/release_notes"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1586214"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1590761"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1591443"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1593058"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1593353"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1593678"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1593798"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1593914"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1594008"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1594028"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1594326"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1594387"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1595457"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1595462"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1595771"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1596336"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1602190"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1607442"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1608849"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1613388"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1613758"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1622632"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1623574"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1625250"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1626475"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1626502"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2745.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2018-3760"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2018-3760"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-3760"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2018/06/19/2"},{"type":"ARTICLE","url":"https://blog.heroku.com/rails-asset-pipeline-vulnerability"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2018-10905"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2018-10905"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-10905"}],"affected":[{"package":{"name":"ansible-tower-server","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/ansible-tower-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.1.8-1.el7at"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}},{"package":{"name":"ansible-tower-setup","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/ansible-tower-setup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.1.8-1.el7at"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}},{"package":{"name":"cfme","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/cfme"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.8.5.1-1.el7cf"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}},{"package":{"name":"cfme-appliance","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/cfme-appliance"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.8.5.1-1.el7cf"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}},{"package":{"name":"cfme-appliance-debuginfo","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/cfme-appliance-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.8.5.1-1.el7cf"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}},{"package":{"name":"cfme-debuginfo","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/cfme-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.8.5.1-1.el7cf"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}},{"package":{"name":"cfme-gemset","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/cfme-gemset"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.8.5.1-1.el7cf"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}},{"package":{"name":"rh-postgresql95-postgresql-pglogical","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/rh-postgresql95-postgresql-pglogical"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.1-2.el7cf"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}},{"package":{"name":"rh-postgresql95-postgresql-pglogical-debuginfo","ecosystem":"Red Hat:cloudforms_managementengine:5.8::el7","purl":"pkg:rpm/redhat/rh-postgresql95-postgresql-pglogical-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.1-2.el7cf"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2018:2745.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}