Show filters
70 Total Results
Displaying 31-40 of 70
Sort by:
Attacker Value
Unknown

CVE-2020-28243

Disclosure Date: February 27, 2021 (last updated February 22, 2025)
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Attacker Value
Unknown

CVE-2020-17490

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
Attacker Value
Unknown

CVE-2020-11652

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Attacker Value
Unknown

CVE-2019-17361

Disclosure Date: January 17, 2020 (last updated February 21, 2025)
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
Attacker Value
Unknown

CVE-2019-19458

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
Attacker Value
Unknown

CVE-2019-19457

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
SALTO ProAccess SPACE 5.4.3.0 allows XSS.
Attacker Value
Unknown

CVE-2019-19460

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.
Attacker Value
Unknown

CVE-2013-2228

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
SaltStack RSA Key Generation allows remote users to decrypt communications
Attacker Value
Unknown

CVE-2019-19459

Disclosure Date: August 07, 2019 (last updated November 27, 2024)
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.
Attacker Value
Unknown

CVE-2019-1010259

Disclosure Date: July 18, 2019 (last updated November 27, 2024)
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.
0