Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h8xp-h3jf-wv4v

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

SaltStack Salt SQL Injection vulnerability in mysql.user_chpass function

SaltStack Salt 2018.3 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt (https://github.com/saltstack/salt/blob/develop/salt/modules/mysql.py#L1462). The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.

Пакеты

Наименование

salt

pip
Затронутые версииВерсия исправления

>= 2018.3.0, < 2018.3.4

2018.3.4

EPSS

Процентиль: 58%
0.0037
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.

CVSS3: 9.8
nvd
больше 6 лет назад

SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.

CVSS3: 9.8
debian
больше 6 лет назад

SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impac ...

EPSS

Процентиль: 58%
0.0037
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89