Описание
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Issue TrackingPatchThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impac ...
SaltStack Salt SQL Injection vulnerability in mysql.user_chpass function
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2