Lucene search

K
osvGoogleOSV:GHSA-PHHW-3WC9-8Q75
HistoryMay 24, 2022 - 5:43 p.m.

SaltStack Salt command injection via a crafted process name

2022-05-2417:43:21
Google
osv.dev
6

8.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

An issue was discovered in SaltStack Salt before 3002.5. The minion’s restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

Rows per page:
1-10 of 1681

References