Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22004

Опубликовано: 02 сент. 2021
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

An improper authentication flaw was found in SaltStack salt before version 3003.3. The Salt minion installer accepts and uses a minion config file at C:\salt\conf if that file is in place before the installer is run. This flaw allows a malicious actor to subvert the proper behavior of the given minion software.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2saltOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2041836salt: allows malacious actor to subvert the proper behaviour of the given minion software

EPSS

Процентиль: 16%
0.00051
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
больше 4 лет назад

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

CVSS3: 6.4
nvd
больше 4 лет назад

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

CVSS3: 6.4
debian
больше 4 лет назад

An issue was discovered in SaltStack Salt before 3003.3. The salt mini ...

CVSS3: 6.4
github
больше 3 лет назад

Improper Authentication in SaltStack Salt

EPSS

Процентиль: 16%
0.00051
Низкий

6.4 Medium

CVSS3