Show filters
55 Total Results
Displaying 21-30 of 55
Sort by:
Attacker Value
Unknown

CVE-2021-3197

Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
Attacker Value
Unknown

CVE-2021-25283

Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
Attacker Value
Unknown

CVE-2021-25282

Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
Attacker Value
Unknown

CVE-2020-35662

Disclosure Date: February 27, 2021 (last updated February 22, 2025)
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
Attacker Value
Unknown

CVE-2020-28243

Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Attacker Value
Unknown

CVE-2020-17490

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
Attacker Value
Unknown

CVE-2020-11652

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Attacker Value
Unknown

CVE-2019-17361

Disclosure Date: January 17, 2020 (last updated February 21, 2025)
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
Attacker Value
Unknown

CVE-2013-2228

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
SaltStack RSA Key Generation allows remote users to decrypt communications
Attacker Value
Unknown

CVE-2019-1010259

Disclosure Date: July 18, 2019 (last updated November 27, 2024)
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.
0