Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Nov 29, 2018 | Oct 24, 2018 |
| Debian | — | Upgrade salt | Jul 30, 2020 | Oct 24, 2018 |
| Freebsd | — | Upgrade py33-saltUpgrade py36-saltUpgrade py27-saltUpgrade py37-saltUpgrade py34-saltUpgrade py35-saltUpgrade py32-salt | Oct 28, 2018 | Oct 27, 2018 |
| Suse | — | Upgrade python2-saltUpgrade salt-docUpgrade salt-cloudUpgrade salt-masterUpgrade salt-bash-completionUpgrade saltUpgrade salt-apiUpgrade salt-zsh-completionUpgrade salt-minionUpgrade salt-proxyUpgrade salt-sshUpgrade python2-distroUpgrade python3-saltUpgrade salt-transactional-updateUpgrade salt-standalone-formulas-configurationUpgrade salt-fish-completionUpgrade python3-distroUpgrade salt-syndic | Nov 20, 2018 | Oct 24, 2018 |
| Ubuntu | — | Upgrade salt-master (Ubuntu Pro)Upgrade salt-minionUpgrade salt-cloud (Ubuntu Pro)Upgrade salt-masterUpgrade salt-common (Ubuntu Pro)Upgrade salt-apiUpgrade salt-proxy (Ubuntu Pro)Upgrade salt-syndic (Ubuntu Pro)Upgrade salt-api (Ubuntu Pro)Upgrade salt-ssh (Ubuntu Pro)Upgrade salt-minion (Ubuntu Pro)Upgrade salt-common | Aug 15, 2020 | Oct 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub