Описание
A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps-legacy/xenial | needed | |
| esm-apps/bionic | needed | |
| esm-apps/jammy | needed | |
| esm-apps/xenial | ignored | end of ESM support, was needed |
| esm-infra-legacy/trusty | needed | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | needed | |
| mantic | DNE |
Показывать по
10
EPSS
Процентиль: 54%
0.0083
Низкий
7.7 High
CVSS3
Связанные уязвимости
CVSS3: 7.7
nvd
около 2 лет назад
A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
CVSS3: 7.7
debian
около 2 лет назад
A specially crafted url can be created which leads to a directory trav ...
CVSS3: 7.7
fstec
больше 2 лет назад
Уязвимость системы управления конфигурациями и удалённого выполнения операций Salt, связанная с созданием специальных URL-адресов, позволяющая нарушителю получить доступ к конфиденциальной информации
EPSS
Процентиль: 54%
0.0083
Низкий
7.7 High
CVSS3