Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.
2017-09-26T14:29:00.597
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | saltstack | salt | ≤ 2015.8.12 | Yes |
Application | saltstack | salt | 2016.3.0 | Yes |
Application | saltstack | salt | 2016.3.1 | Yes |
Application | saltstack | salt | 2016.3.2 | Yes |
Application | saltstack | salt | 2016.3.3 | Yes |
Application | saltstack | salt | 2016.3.4 | Yes |
Application | saltstack | salt | 2016.11.0 | Yes |
Application | saltstack | salt | 2016.11.1 | Yes |
Application | saltstack | salt | 2016.11.2 | Yes |