Описание
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| salt | fixed | 2018.3.3+dfsg1-1 | package | |
| salt | not-affected | jessie | package |
Примечания
Fixed in 2016.11.10, 2017.7.8, 2018.3.3
https://docs.saltstack.com/en/latest/topics/releases/2016.11.10.html#security-fix
minimal patch: https://github.com/saltstack/salt/compare/v2016.11.9..v2016.11.10
Связанные уязвимости
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
SaltStack Salt Directory Traversal vulnerability in salt-api
Уязвимость компонента salt-api системы управления конфигурациями SaltStack, позволяющая нарушителю получить доступ к конфиденциальным данным