Vulnerabilities
Vulnerable Software
Saltstack:  >> Salt  >> 2015.8.13  Security Vulnerabilities
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
CVSS Score
5.3
EPSS Score
0.012
Published
2018-10-24
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
CVSS Score
9.8
EPSS Score
0.009
Published
2018-10-24
In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.
CVSS Score
9.8
EPSS Score
0.005
Published
2018-04-23
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.
CVSS Score
9.8
EPSS Score
0.004
Published
2017-10-24
SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
CVSS Score
7.5
EPSS Score
0.027
Published
2017-10-24
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
CVSS Score
9.8
EPSS Score
0.014
Published
2017-08-23


Contact Us

Shodan ® - All rights reserved