Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77w2-v593-vxvv

Опубликовано: 30 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.3
CVSS3: 7.8

Описание

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

Пакеты

Наименование

salt

pip
Затронутые версииВерсия исправления

< 3006.17

3006.17

EPSS

Процентиль: 1%
0.00009
Низкий

7.3 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.8
ubuntu
6 дней назад

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

CVSS3: 7.8
nvd
8 дней назад

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

CVSS3: 7.8
debian
8 дней назад

Salt's junos execution module contained an unsafe YAML decode/load usa ...

suse-cvrf
около 2 месяцев назад

Security update for salt

suse-cvrf
около 2 месяцев назад

Security update for salt

EPSS

Процентиль: 1%
0.00009
Низкий

7.3 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-94