Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pf7h-h2wq-m7pg

Опубликовано: 21 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Exposure of Resource to Wrong Sphere in salt

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

Пакеты

Наименование

salt

pip
Затронутые версииВерсия исправления

< 3003.3

3003.3

EPSS

Процентиль: 86%
0.02739
Низкий

7.5 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

CVSS3: 7.5
redhat
больше 4 лет назад

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

CVSS3: 7.5
nvd
больше 4 лет назад

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

CVSS3: 7.5
debian
больше 4 лет назад

An issue was discovered in SaltStack Salt before 3003.3. A user who ha ...

suse-cvrf
больше 4 лет назад

Security update for salt

EPSS

Процентиль: 86%
0.02739
Низкий

7.5 High

CVSS3

Дефекты

CWE-668