Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Nov 29, 2018 | Oct 24, 2018 |
| Debian | — | Upgrade salt | Jul 30, 2020 | Oct 24, 2018 |
| Freebsd | — | Upgrade py37-saltUpgrade py34-saltUpgrade py32-saltUpgrade py27-saltUpgrade py35-saltUpgrade py36-saltUpgrade py33-salt | Oct 28, 2018 | Oct 27, 2018 |
| Suse | — | Upgrade python3-saltUpgrade salt-standalone-formulas-configurationUpgrade python2-distroUpgrade salt-fish-completionUpgrade salt-transactional-updateUpgrade salt-syndicUpgrade python3-distroUpgrade salt-masterUpgrade salt-bash-completionUpgrade salt-sshUpgrade salt-minionUpgrade salt-proxyUpgrade python2-saltUpgrade salt-zsh-completionUpgrade salt-apiUpgrade salt-docUpgrade salt-cloudUpgrade salt | Nov 20, 2018 | Oct 24, 2018 |
| Ubuntu | — | Upgrade salt-commonUpgrade salt-ssh (Ubuntu Pro)Upgrade salt-api (Ubuntu Pro)Upgrade salt-minion (Ubuntu Pro)Upgrade salt-masterUpgrade salt-syndic (Ubuntu Pro)Upgrade salt-proxy (Ubuntu Pro)Upgrade salt-master (Ubuntu Pro)Upgrade salt-common (Ubuntu Pro)Upgrade salt-cloud (Ubuntu Pro)Upgrade salt-minionUpgrade salt-api | Aug 15, 2020 | Oct 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub