Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2rp-9cpj-pfw2

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.6

Описание

Salt Insecure configuration of PAM external authentication service

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

Пакеты

Наименование

salt

pip
Затронутые версииВерсия исправления

< 2015.5.10

2015.5.10

Наименование

salt

pip
Затронутые версииВерсия исправления

>= 2015.8, < 2015.8.8

2015.8.8

EPSS

Процентиль: 56%
0.00873
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 9 лет назад

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

redhat
больше 10 лет назад

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

CVSS3: 5.6
nvd
больше 9 лет назад

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

CVSS3: 5.6
debian
больше 9 лет назад

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external ...

EPSS

Процентиль: 56%
0.00873
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-287