Lucene search

K
osvGoogleOSV:PYSEC-2021-55
HistoryFeb 27, 2021 - 5:15 a.m.

PYSEC-2021-55

2021-02-2705:15:00
Google
osv.dev
9
saltstack
command injection
web requests

EPSS

0.059

Percentile

93.5%

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.