Описание
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 1.2 | salt | Not affected | ||
| Red Hat Ceph Storage 1.3 | salt | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1305460salt: Improper handling of clear messages on the minion
4.3 Medium
CVSS2
Связанные уязвимости
CVSS3: 8.1
ubuntu
больше 10 лет назад
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
CVSS3: 8.1
nvd
больше 10 лет назад
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
CVSS3: 8.1
debian
больше 10 лет назад
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages ...
4.3 Medium
CVSS2