Lucene search

K
osvGoogleOSV:GHSA-QR38-H96J-2J3W
HistoryMay 24, 2022 - 5:33 p.m.

SaltStack Salt Command Injection in netapi ssh client

2022-05-2417:33:18
Google
osv.dev
3

9.4 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

References