Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjhf-vpx3-33r3

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

SaltStack Salt Unauthenticated Remote Code Execution

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

Пакеты

Наименование

salt

pip
Затронутые версииВерсия исправления

< 2019.2.4

2019.2.4

Наименование

salt

pip
Затронутые версииВерсия исправления

>= 3000, < 3000.2

3000.2

EPSS

Процентиль: 100%
0.94421
Критический

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-306

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CVSS3: 9.8
redhat
почти 6 лет назад

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CVSS3: 9.8
nvd
почти 6 лет назад

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CVSS3: 9.8
debian
почти 6 лет назад

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 bef ...

CVSS3: 9.8
fstec
почти 6 лет назад

Уязвимость компонента master.py системы управления конфигурациями и удалённого выполнения операций SaltStack, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 100%
0.94421
Критический

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-306