Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29526
HistoryMar 01, 2021 - 5:52 a.m.

Insecure Session Management

2021-03-0105:52:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
insecure session management
eauth tokens
expiration
salt master
salt minions
commands

EPSS

0.054

Percentile

93.2%

salt uses an insecure session management. The eauth tokens are not invalidated upon expiration, allowing usage thereafter and these session tokens can be used to run commands against the salt master and minions.