Skip to content
Noroxi

SaltStack records

56 published records for vendor saltstack.

All records

56 records
  • An issue was discovered in SaltStack Salt through 3002.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    saltstack · saltNov 6, 2020

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    saltstack · saltApr 30, 2020

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    MediumCVSS 6.5KEVWeaponizedEPSS 86%

    saltstack · saltApr 30, 2020

  • CVE-2021-25282
    64This week

    An issue was discovered in through SaltStack Salt before 3002.5.

    CriticalCVSS 9.1WeaponizedEPSS 92%

    saltstack · saltFeb 27, 2021

  • CVE-2021-25281
    61This week

    An issue was discovered in through SaltStack Salt before 3002.5.

    CriticalCVSS 9.8WeaponizedEPSS 73%

    saltstack · saltFeb 27, 2021

  • CVE-2021-3197
    61This week

    An issue was discovered in SaltStack Salt before 3002.5.

    CriticalCVSS 9.8No exploitEPSS 72%

    saltstack · saltFeb 27, 2021

  • In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens.

    CriticalCVSS 9.8WeaponizedEPSS 58%

    saltstack · saltNov 6, 2020

  • In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection.

    CriticalCVSS 9.8No exploitEPSS 15%

    saltstack · saltJan 16, 2020

  • An issue was discovered in through SaltStack Salt before 3002.5.

    CriticalCVSS 9.8No exploitEPSS 11%

    saltstack · saltFeb 27, 2021

  • An issue was discovered in SaltStack Salt before 3002.5.

    CriticalCVSS 9.8No exploitEPSS 8%

    saltstack · saltFeb 27, 2021

  • SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands v

    CriticalCVSS 9.8No exploitEPSS 5%

    saltstack · saltOct 24, 2018

  • The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote atta

    CriticalCVSS 10.0No exploitEPSS 3%

    saltstack · saltNov 5, 2013

  • Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote mini

    CriticalCVSS 9.8No exploitEPSS 5%

    saltstack · saltAug 23, 2017

  • Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before

    CriticalCVSS 9.8No exploitEPSS 3%

    saltstack · saltOct 24, 2017

  • win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in de

    CriticalCVSS 9.8No exploitEPSS 2%

    saltstack · salt 2015Aug 9, 2017

  • SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection.

    CriticalCVSS 9.8No exploitEPSS 2%

    saltstack · salt 2018Jul 18, 2019

  • Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."

    CriticalCVSS 10.0No exploitEPSS 1%

    saltstack · saltNov 5, 2013

  • Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/mo

    CriticalCVSS 9.8No exploitEPSS 2%

    saltstack · saltFeb 17, 2023

  • CVE-2017-7893
    39Monitor

    In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.

    CriticalCVSS 9.8No exploitEPSS 1%

    saltstack · saltApr 23, 2018

  • CVE-2021-3144
    38Monitor

    In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration.

    CriticalCVSS 9.1No exploitEPSS 5%

    saltstack · saltFeb 27, 2021

  • CVE-2013-4436
    38Monitor

    The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote at

    CriticalCVSS 9.3No exploitEPSS 2%

    saltstack · saltNov 5, 2013

  • CVE-2016-9639
    37Monitor

    Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.

    CriticalCVSS 9.1No exploitEPSS 3%

    saltstack · saltFeb 7, 2017

  • CVE-2017-5200
    36Monitor

    Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on

    HighCVSS 8.8No exploitEPSS 3%

    saltstack · saltSep 26, 2017

  • An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2.

    HighCVSS 8.8No exploitEPSS 2%

    saltstack · saltJun 23, 2022

  • CVE-2017-5192
    36Monitor

    When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2

    HighCVSS 8.8No exploitEPSS 2%

    saltstack · saltSep 26, 2017