Описание
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:saltstack:salt:0.15.0:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.15.1:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.16.0:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.16.2:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.16.3:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.16.4:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.17.0:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00324
Низкий
6 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
ubuntu
больше 12 лет назад
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.
debian
больше 12 лет назад
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated ...
CVSS3: 8.8
github
больше 3 лет назад
Salt has insufficient argument validation in several modules
EPSS
Процентиль: 55%
0.00324
Низкий
6 Medium
CVSS2
Дефекты
CWE-287