SaltStack Salt Remote command execution and incorrect access control when using salt-api
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 23, 2024
Package
Affected versions
>= 2017.7.0, < 2017.7.8
>= 2018.3.0, < 2018.3.3
>= 2016.11.0, < 2016.11.10
Patched versions
2017.7.8
2018.3.3
2016.11.10
Description
Published by the National Vulnerability Database
Oct 24, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Apr 22, 2024
Last updated
Oct 23, 2024
SaltStack Salt 2016.11.x before 2016.11.10, 2017.7.x before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
References