Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpxm-fprw-6hxj

Опубликовано: 25 июн. 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

Salt's PAM auth fails to reject locked accounts

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

Пакеты

Наименование

salt

pip
Затронутые версииВерсия исправления

< 3002.9

3002.9

Наименование

salt

pip
Затронутые версииВерсия исправления

>= 3003.0, < 3003.5

3003.5

Наименование

salt

pip
Затронутые версииВерсия исправления

>= 3004.0, < 3004.2

3004.2

EPSS

Процентиль: 67%
0.00536
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

CVSS3: 8.8
nvd
больше 3 лет назад

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

CVSS3: 8.8
debian
больше 3 лет назад

An issue was discovered in SaltStack Salt in versions before 3002.9, 3 ...

suse-cvrf
больше 3 лет назад

Security update for salt

suse-cvrf
больше 3 лет назад

Security update for salt

EPSS

Процентиль: 67%
0.00536
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-863