Описание
Salt vulnerable to arbitrary event injection
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.
Пакеты
salt
>= 3006.0rc1, < 3006.12
3006.12
salt
>= 3007.0rc1, < 3007.4
3007.4
Связанные уязвимости
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.
Arbitrary event injection on Salt Master. The master's "_minion_event" ...
Уязвимость метода _minion_event мастера системы управления конфигурациями и удалённого выполнения операций Salt, позволяющая нарушителю выполнять произвольные команды