Lucene search

K
osvGoogleOSV:GHSA-8R7R-X48R-PF8F
HistoryMay 13, 2022 - 1:46 a.m.

SaltStack Salt arbitrary command execution in Salt-api via ssh_client

2022-05-1301:46:08
Google
osv.dev
8
saltstack
arbitrary command execution
ssh_client
software

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

61.7%

Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt’s ssh_client.

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

61.7%