Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46753
HistoryMay 06, 2024 - 6:27 a.m.

Improper Authentication

2024-05-0606:27:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
improper authentication
saltstack
routine execution
authenticated users
privileges
bypass restrictions

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

61.6%

Salt (aka SaltStack) is vulnerable to Improper Authentication. The vulnerability is due to a lack of authentication during routine execution, allowing authenticated users with certain privileges to bypass restrictions by nesting restricted routines within other routines.

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

61.6%