Описание
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:saltstack:salt:0.15.0:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.15.1:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.16.0:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.16.2:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.16.3:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.16.4:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:0.17.0:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.01515
Низкий
6 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
ubuntu
почти 13 лет назад
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.
debian
почти 13 лет назад
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated ...
CVSS3: 8.8
github
больше 4 лет назад
Salt has insufficient argument validation in several modules
EPSS
Процентиль: 73%
0.01515
Низкий
6 Medium
CVSS2
Дефекты
CWE-287