rpm package
suse/salt&distro=SUSE Manager Proxy 3.1
pkg:rpm/suse/salt&distro=SUSE%20Manager%20Proxy%203.1
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-15751 | — | < 2018.3.0-46.44.1 | 2018.3.0-46.44.1 | Oct 24, 2018 | SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi). | ||
| CVE-2018-15750 | — | < 2018.3.0-46.44.1 | 2018.3.0-46.44.1 | Oct 24, 2018 | Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server. | ||
| CVE-2017-14696 | Hig | 7.5 | < 2016.11.4-46.10.1 | 2016.11.4-46.10.1 | Oct 24, 2017 | SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request. | |
| CVE-2017-14695 | Cri | 9.8 | < 2016.11.4-46.10.1 | 2016.11.4-46.10.1 | Oct 24, 2017 | Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability ex | |
| CVE-2017-12791 | Cri | 9.8 | < 2016.11.4-4.3.1 | 2016.11.4-4.3.1 | Aug 23, 2017 | Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. |
- CVE-2018-15751Oct 24, 2018affected < 2018.3.0-46.44.1fixed 2018.3.0-46.44.1
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
- CVE-2018-15750Oct 24, 2018affected < 2018.3.0-46.44.1fixed 2018.3.0-46.44.1
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
- affected < 2016.11.4-46.10.1fixed 2016.11.4-46.10.1
SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
- affected < 2016.11.4-46.10.1fixed 2016.11.4-46.10.1
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability ex
- affected < 2016.11.4-4.3.1fixed 2016.11.4-4.3.1
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.