Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Nov 29, 2018 | Oct 24, 2018 |
| Debian | — | Upgrade salt | Jul 30, 2020 | Oct 24, 2018 |
| Freebsd | — | Upgrade py37-saltUpgrade py34-saltUpgrade py27-saltUpgrade py32-saltUpgrade py35-saltUpgrade py33-saltUpgrade py36-salt | Oct 28, 2018 | Oct 27, 2018 |
| Suse | — | Upgrade salt-syndicUpgrade python3-distroUpgrade salt-transactional-updateUpgrade salt-fish-completionUpgrade python2-distroUpgrade python3-saltUpgrade salt-standalone-formulas-configurationUpgrade saltUpgrade salt-bash-completionUpgrade salt-apiUpgrade salt-minionUpgrade salt-sshUpgrade salt-cloudUpgrade python2-saltUpgrade salt-zsh-completionUpgrade salt-proxyUpgrade salt-docUpgrade salt-master | Nov 20, 2018 | Oct 24, 2018 |
| Ubuntu | — | Upgrade salt-cloud (Ubuntu Pro)Upgrade salt-proxy (Ubuntu Pro)Upgrade salt-common (Ubuntu Pro)Upgrade salt-masterUpgrade salt-minionUpgrade salt-master (Ubuntu Pro)Upgrade salt-apiUpgrade salt-syndic (Ubuntu Pro)Upgrade salt-api (Ubuntu Pro)Upgrade salt-commonUpgrade salt-minion (Ubuntu Pro)Upgrade salt-ssh (Ubuntu Pro) | Aug 15, 2020 | Oct 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub