SaltStack
by Saltstack
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33226 | Cri | 0.64 | 9.8 | 0.02 | Feb 17, 2023 | Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input | ||
| CVE-2013-2228 | Hig | 0.53 | 8.1 | 0.02 | Dec 3, 2019 | SaltStack RSA Key Generation allows remote users to decrypt communications |
- risk 0.64cvss 9.8epss 0.02
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input
- risk 0.53cvss 8.1epss 0.02
SaltStack RSA Key Generation allows remote users to decrypt communications