VYPR

SaltStack

by Saltstack

Source repositories

CVEs (6)

  • CVE-2020-16846CriKEVNov 6, 2020
    risk 0.80cvss 9.8epss 1.00

    An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

  • CVE-2021-33226CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input

  • CVE-2020-25592CriNov 6, 2020
    risk 0.64cvss 9.8epss 0.58

    In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

  • CVE-2021-31607HigApr 23, 2021
    risk 0.51cvss 7.8epss 0.06

    In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the…

  • CVE-2013-2228HigDec 3, 2019
    risk 0.46cvss 8.1epss 0.02

    SaltStack RSA Key Generation allows remote users to decrypt communications

  • CVE-2020-17490MedNov 6, 2020
    risk 0.36cvss 5.5epss 0.00

    The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.