[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.5] salt: multiple issues (CVE-2017-5192, CVE-2017-5200)

ID: oval:org.secpod.oval:def:1800438Date: (C)2018-03-28   (M)2023-12-20
Class: PATCHFamily: unix




CVE-2017-5192: local_batch client external authentication not respected The `LocalClient.cmd_batch` method client does not accept `external_auth` credentials and so access to it from salt-api has been removed for now. This vulnerability allows code execution for already- authenticated users and is only in effect when running salt-api as the `root` user. Fixed In Version salt 2015.8.13, salt 2016.3.5, salt 2016.11.2 Reference CVE-2017-5200: Salt-api allows arbitrary command execution on a salt-master via Salt"s ssh_client Users of Salt-API and salt-ssh could execute a command on the salt master via a hole when both systems were enabled. Fixed In Version salt 2015.8.13, salt 2016.3.5, salt 2016.11.2 Reference

Platform:
Alpine Linux 3.5
Product:
salt
Reference:
6803
CVE-2017-5192
CVE-2017-5200
CVE    2
CVE-2017-5200
CVE-2017-5192
CPE    2
cpe:/a:saltstack:salt
cpe:/o:alpinelinux:alpine_linux:3.5

© SecPod Technologies