Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-62349

Опубликовано: 30 янв. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.2

Описание

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
jammy

not-affected

code not present
noble

DNE

questing

DNE

upstream

released

3006.17

Показывать по

EPSS

Процентиль: 33%
0.00407
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
6 месяцев назад

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

CVSS3: 6.2
debian
6 месяцев назад

Salt contains an authentication protocol version downgrade weakness th ...

CVSS3: 6.2
github
6 месяцев назад

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

CVSS3: 6.7
fstec
6 месяцев назад

Уязвимость системы управления конфигурациями и удалённого выполнения операций Salt, связанная с недостатками процедуры аутентификации, позволяющая нарушителю повысить свои привилегии

suse-cvrf
8 месяцев назад

Security update for salt

EPSS

Процентиль: 33%
0.00407
Низкий

6.2 Medium

CVSS3