Описание
Salt has minion event bus authorization bypass vulnerability
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
Пакеты
Наименование
salt
pip
Затронутые версииВерсия исправления
>= 3007.0, < 3007.4
3007.4
Наименование
salt
pip
Затронутые версииВерсия исправления
>= 3006.0, < 3006.12
3006.12
Связанные уязвимости
CVSS3: 8.1
ubuntu
3 месяца назад
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
CVSS3: 8.1
nvd
3 месяца назад
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
CVSS3: 8.1
debian
3 месяца назад
Minion event bus authorization bypass. An attacker with access to a mi ...