Show filters
55 Total Results
Displaying 21-30 of 55
Sort by:
Attacker Value
Unknown
CVE-2021-3197
Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
0
Attacker Value
Unknown
CVE-2021-25283
Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
0
Attacker Value
Unknown
CVE-2021-25282
Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
0
Attacker Value
Unknown
CVE-2020-35662
Disclosure Date: February 27, 2021 (last updated February 22, 2025)
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
0
Attacker Value
Unknown
CVE-2020-28243
Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
0
Attacker Value
Unknown
CVE-2020-17490
Disclosure Date: November 06, 2020 (last updated February 22, 2025)
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
0
Attacker Value
Unknown
CVE-2020-11652
Disclosure Date: April 30, 2020 (last updated February 21, 2025)
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
0
Attacker Value
Unknown
CVE-2019-17361
Disclosure Date: January 17, 2020 (last updated February 21, 2025)
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
0
Attacker Value
Unknown
CVE-2013-2228
Disclosure Date: December 03, 2019 (last updated November 27, 2024)
SaltStack RSA Key Generation allows remote users to decrypt communications
0
Attacker Value
Unknown
CVE-2019-1010259
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.
0