Lucene search

K
osvGoogleOSV:GHSA-GHC2-HX3W-JQMP
HistoryMay 24, 2022 - 5:43 p.m.

SaltStack Salt command injection in the Salt-API when using the Salt-SSH client

2022-05-2417:43:23
Google
osv.dev
6
saltstack
salt-api
command injection

AI Score

9.6

Confidence

High

EPSS

0.059

Percentile

93.5%

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.

References