Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28243

Опубликовано: 25 фев. 2021
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

A flaw was found in Salt. A privilege escalation is possible on a SaltStack minion when an unprivileged user can create files in any non-blacklisted directory via command injection in a process name. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

Salt has been deprecated as of Red Hat Ceph Storage 2.5, as Salt was used to install RHSCON-2 and RHSCON-2 has reached End Of Life.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2saltWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1933350salt: Privilege escalation on a minion when an unprivileged user is able to create files in any non-blacklisted directory

EPSS

Процентиль: 82%
0.01734
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

CVSS3: 7.8
nvd
почти 5 лет назад

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

CVSS3: 7.8
debian
почти 5 лет назад

An issue was discovered in SaltStack Salt before 3002.5. The minion's ...

CVSS3: 7.8
github
больше 3 лет назад

SaltStack Salt command injection via a crafted process name

CVSS3: 7.8
fstec
почти 5 лет назад

Уязвимость системы управления конфигурациями и удалённого выполнения операций SaltStack Salt, позволяющая нарушителю локально повысить привилегии.

EPSS

Процентиль: 82%
0.01734
Низкий

7 High

CVSS3