Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Nov 29, 2018 | Oct 24, 2018 |
| Debian | — | Upgrade salt | Jul 30, 2020 | Oct 24, 2018 |
| Freebsd | — | Upgrade py34-saltUpgrade py35-saltUpgrade py27-saltUpgrade py32-saltUpgrade py37-saltUpgrade py36-saltUpgrade py33-salt | Oct 28, 2018 | Oct 27, 2018 |
| Suse | — | Upgrade salt-minionUpgrade salt-sshUpgrade salt-apiUpgrade salt-bash-completionUpgrade salt-proxyUpgrade salt-masterUpgrade salt-zsh-completionUpgrade salt-cloudUpgrade python2-saltUpgrade salt-docUpgrade saltUpgrade python3-distroUpgrade python2-distroUpgrade salt-standalone-formulas-configurationUpgrade salt-fish-completionUpgrade python3-saltUpgrade salt-syndicUpgrade salt-transactional-update | Nov 20, 2018 | Oct 24, 2018 |
| Ubuntu | — | Upgrade salt-commonUpgrade salt-ssh (Ubuntu Pro)Upgrade salt-api (Ubuntu Pro)Upgrade salt-minion (Ubuntu Pro)Upgrade salt-cloud (Ubuntu Pro)Upgrade salt-proxy (Ubuntu Pro)Upgrade salt-minionUpgrade salt-master (Ubuntu Pro)Upgrade salt-masterUpgrade salt-syndic (Ubuntu Pro)Upgrade salt-common (Ubuntu Pro)Upgrade salt-api | Aug 15, 2020 | Oct 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub