Search CVE reports


Toggle filters

41 – 50 of 71 results


CVE-2020-11652

Medium priority

Some fixes available 3 of 4

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory...

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Fixed
Show less packages

CVE-2020-11651

Medium priority

Some fixes available 3 of 4

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods...

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Fixed
Show less packages

CVE-2019-18897

Medium priority
Ignored

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to...

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected
Show less packages

CVE-2019-17361

Medium priority

Some fixes available 2 of 5

In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on...

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Fixed
Show less packages

CVE-2019-1010259

Medium priority
Needs evaluation

SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from...

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Needs evaluation
Show less packages

CVE-2018-15751

Medium priority

Some fixes available 4 of 7

SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not affected Not in release Fixed
Show less packages

CVE-2018-15750

Medium priority

Some fixes available 4 of 7

Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not affected Not in release Fixed
Show less packages

CVE-2017-8109

Medium priority
Ignored

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not affected
Show less packages

CVE-2017-7893

Medium priority
Vulnerable

In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Not affected
Show less packages

CVE-2017-5200

Medium priority
Vulnerable

Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client. Users of Salt-API and salt-ssh could execute a...

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Not affected
Show less packages