rpm package
suse/salt&distro=SUSE Linux Enterprise Module for Python 2 15 SP2
pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP2
Vulnerabilities (13)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-3197 | Cri | 9.8 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request. | |
| CVE-2021-3148 | Cri | 9.8 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py. | |
| CVE-2021-3144 | Cri | 9.1 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.) | |
| CVE-2021-25284 | Med | 4.4 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level. | |
| CVE-2021-25283 | Cri | 9.8 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks. | |
| CVE-2021-25282 | Cri | 9.1 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. | |
| CVE-2021-25281 | Cri | 9.8 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master. | |
| CVE-2020-35662 | Hig | 7.4 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. | |
| CVE-2020-28972 | Med | 5.9 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate. | |
| CVE-2020-28243 | Hig | 7.8 | < 3000-24.1 | 3000-24.1 | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory. | |
| CVE-2020-25592 | Cri | 9.8 | < 3000-4.20.1 | 3000-4.20.1 | Nov 6, 2020 | In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH. | |
| CVE-2020-17490 | Med | 5.5 | < 3000-4.20.1 | 3000-4.20.1 | Nov 6, 2020 | The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions. | |
| CVE-2020-16846 | Cri | 9.8 | KEV | < 3000-4.20.1 | 3000-4.20.1 | Nov 6, 2020 | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. |
- affected < 3000-24.1fixed 3000-24.1
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
- affected < 3000-24.1fixed 3000-24.1
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.
- affected < 3000-24.1fixed 3000-24.1
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
- affected < 3000-24.1fixed 3000-24.1
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
- affected < 3000-24.1fixed 3000-24.1
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
- affected < 3000-24.1fixed 3000-24.1
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
- affected < 3000-24.1fixed 3000-24.1
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
- affected < 3000-24.1fixed 3000-24.1
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
- affected < 3000-24.1fixed 3000-24.1
In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.
- affected < 3000-24.1fixed 3000-24.1
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
- affected < 3000-4.20.1fixed 3000-4.20.1
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
- affected < 3000-4.20.1fixed 3000-4.20.1
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
- affected < 3000-4.20.1fixed 3000-4.20.1
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.