Lucene search

K
osvGoogleOSV:GHSA-XGMH-GFXW-2HVV
HistoryMay 24, 2022 - 5:43 p.m.

SaltStack Salt Server Side Template Injection

2022-05-2417:43:22
Google
osv.dev
9
saltstack
server side
template injection
jinja renderer
security issue

AI Score

9.5

Confidence

High

EPSS

0.167

Percentile

96.1%

An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.

References