Записи saltstack
56 опубликованных записей вендора saltstack.
Профиль для исследователя
- Попали в KEV
- 3 · 5,4 %
- С эксплойтом
- 6 · 10,7 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- 552 дн.
Повторяющиеся классы
- CWE-287 Improper Authentication8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-295 Improper Certificate Validation3
- CWE-284 Improper Access Control2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
56 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2020-16846Готовый эксплойт | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Критическая9,8 | KEV | 99,6 % | 6 нояб. 2020 г. |
98Срочно | CVE-2020-11651Готовый эксплойт | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Критическая9,8 | KEV | 96,6 % | 30 апр. 2020 г. |
82Срочно | CVE-2020-11652Готовый эксплойт | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt · CWE-22 | Средняя6,5 | KEV | 86,2 % | 30 апр. 2020 г. |
64На этой неделе | CVE-2021-25282Готовый эксплойт | An issue was discovered in through SaltStack Salt before 3002.5.saltstack · salt · CWE-22 | Критическая9,1 | — | 92,4 % | 27 февр. 2021 г. |
61На этой неделе | CVE-2021-25281Готовый эксплойт | An issue was discovered in through SaltStack Salt before 3002.5.saltstack · salt · CWE-287 | Критическая9,8 | — | 73,1 % | 27 февр. 2021 г. |
61На этой неделе | CVE-2021-3197Эксплойта нет | An issue was discovered in SaltStack Salt before 3002.5.saltstack · salt · CWE-74 | Критическая9,8 | — | 72,3 % | 27 февр. 2021 г. |
56В плане | CVE-2020-25592Готовый эксплойт | In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens.saltstack · salt · CWE-287 | Критическая9,8 | — | 57,7 % | 6 нояб. 2020 г. |
44В плане | CVE-2019-17361Эксплойта нет | In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection.saltstack · salt · CWE-77 | Критическая9,8 | — | 15,2 % | 16 янв. 2020 г. |
42В плане | CVE-2021-25283Эксплойта нет | An issue was discovered in through SaltStack Salt before 3002.5.saltstack · salt · CWE-94 | Критическая9,8 | — | 10,5 % | 27 февр. 2021 г. |
41В плане | CVE-2021-3148Эксплойта нет | An issue was discovered in SaltStack Salt before 3002.5.saltstack · salt · CWE-77 | Критическая9,8 | — | 8,2 % | 27 февр. 2021 г. |
41В плане | CVE-2018-15751Эксплойта нет | SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands vsaltstack · salt · CWE-287 | Критическая9,8 | — | 5,2 % | 24 окт. 2018 г. |
41В плане | CVE-2013-6617Эксплойта нет | The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attasaltstack · salt · CWE-264 | Критическая10,0 | — | 3,0 % | 5 нояб. 2013 г. |
40В плане | CVE-2017-12791Эксплойта нет | Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minisaltstack · salt · CWE-22 | Критическая9,8 | — | 4,7 % | 23 авг. 2017 г. |
40В плане | CVE-2017-14695Эксплойта нет | Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x beforesaltstack · salt · CWE-22 | Критическая9,8 | — | 2,6 % | 24 окт. 2017 г. |
40В плане | CVE-2015-6941Эксплойта нет | win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in desaltstack · salt 2015 · CWE-534 | Критическая9,8 | — | 2,2 % | 9 авг. 2017 г. |
40В плане | CVE-2019-1010259Эксплойта нет | SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection.saltstack · salt 2018 · CWE-89 | Критическая9,8 | — | 1,9 % | 18 июл. 2019 г. |
40В плане | CVE-2013-4437Эксплойта нет | Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."saltstack · salt | Критическая10,0 | — | 1,5 % | 5 нояб. 2013 г. |
39Наблюдать | CVE-2021-33226Эксплойта нет | Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/mosaltstack · salt · CWE-120 | Критическая9,8 | — | 1,6 % | 17 февр. 2023 г. |
39Наблюдать | CVE-2017-7893Эксплойта нет | In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.saltstack · salt | Критическая9,8 | — | 1,4 % | 23 апр. 2018 г. |
38Наблюдать | CVE-2021-3144Эксплойта нет | In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration.saltstack · salt · CWE-613 | Критическая9,1 | — | 5,2 % | 27 февр. 2021 г. |
38Наблюдать | CVE-2013-4436Эксплойта нет | The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote atsaltstack · salt · CWE-20 | Критическая9,3 | — | 1,8 % | 5 нояб. 2013 г. |
37Наблюдать | CVE-2016-9639Эксплойта нет | Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.saltstack · salt · CWE-284 | Критическая9,1 | — | 2,6 % | 7 февр. 2017 г. |
36Наблюдать | CVE-2017-5200Эксплойта нет | Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on saltstack · salt | Высокая8,8 | — | 3,2 % | 26 сент. 2017 г. |
36Наблюдать | CVE-2022-22967Эксплойта нет | An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2.saltstack · salt · CWE-863 | Высокая8,8 | — | 2,1 % | 23 июн. 2022 г. |
36Наблюдать | CVE-2017-5192Эксплойта нет | When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2saltstack · salt · CWE-287 | Высокая8,8 | — | 1,7 % | 26 сент. 2017 г. |
- CVE-2020-1684699Срочно
An issue was discovered in SaltStack Salt through 3002.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %saltstack · salt6 нояб. 2020 г.
- CVE-2020-1165198Срочно
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %saltstack · salt30 апр. 2020 г.
- CVE-2020-1165282Срочно
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 86 %saltstack · salt30 апр. 2020 г.
- CVE-2021-2528264На этой неделе
An issue was discovered in through SaltStack Salt before 3002.5.
КритическаяCVSS 9,1Готовый эксплойтEPSS 92 %saltstack · salt27 февр. 2021 г.
- CVE-2021-2528161На этой неделе
An issue was discovered in through SaltStack Salt before 3002.5.
КритическаяCVSS 9,8Готовый эксплойтEPSS 73 %saltstack · salt27 февр. 2021 г.
- CVE-2021-319761На этой неделе
An issue was discovered in SaltStack Salt before 3002.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 72 %saltstack · salt27 февр. 2021 г.
- CVE-2020-2559256В плане
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens.
КритическаяCVSS 9,8Готовый эксплойтEPSS 58 %saltstack · salt6 нояб. 2020 г.
- CVE-2019-1736144В плане
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %saltstack · salt16 янв. 2020 г.
- CVE-2021-2528342В плане
An issue was discovered in through SaltStack Salt before 3002.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %saltstack · salt27 февр. 2021 г.
- CVE-2021-314841В плане
An issue was discovered in SaltStack Salt before 3002.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %saltstack · salt27 февр. 2021 г.
- CVE-2018-1575141В плане
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands v
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %saltstack · salt24 окт. 2018 г.
- CVE-2013-661741В плане
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote atta
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %saltstack · salt5 нояб. 2013 г.
- CVE-2017-1279140В плане
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote mini
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %saltstack · salt23 авг. 2017 г.
- CVE-2017-1469540В плане
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %saltstack · salt24 окт. 2017 г.
- CVE-2015-694140В плане
win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in de
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %saltstack · salt 20159 авг. 2017 г.
- CVE-2019-101025940В плане
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %saltstack · salt 201818 июл. 2019 г.
- CVE-2013-443740В плане
Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %saltstack · salt5 нояб. 2013 г.
- CVE-2021-3322639Наблюдать
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/mo
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %saltstack · salt17 февр. 2023 г.
- CVE-2017-789339Наблюдать
In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %saltstack · salt23 апр. 2018 г.
- CVE-2021-314438Наблюдать
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration.
КритическаяCVSS 9,1Эксплойта нетEPSS 5 %saltstack · salt27 февр. 2021 г.
- CVE-2013-443638Наблюдать
The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote at
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %saltstack · salt5 нояб. 2013 г.
- CVE-2016-963937Наблюдать
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %saltstack · salt7 февр. 2017 г.
- CVE-2017-520036Наблюдать
Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %saltstack · salt26 сент. 2017 г.
- CVE-2022-2296736Наблюдать
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %saltstack · salt23 июн. 2022 г.
- CVE-2017-519236Наблюдать
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %saltstack · salt26 сент. 2017 г.