Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqh4-crjf-jjxx

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Salt Improper Access Control

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

Пакеты

Наименование

salt

pip
Затронутые версииВерсия исправления

>= 2015.8.0rc1, < 2015.8.4

2015.8.4

EPSS

Процентиль: 70%
0.00628
Низкий

8.1 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

redhat
около 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

CVSS3: 8.1
nvd
почти 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

CVSS3: 8.1
debian
почти 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages ...

suse-cvrf
почти 10 лет назад

Security update for salt

EPSS

Процентиль: 70%
0.00628
Низкий

8.1 High

CVSS3

Дефекты

CWE-284