Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Nov 29, 2018 | Oct 24, 2018 |
| Debian | — | Upgrade salt | Jul 30, 2020 | Oct 24, 2018 |
| Freebsd | — | Upgrade py33-saltUpgrade py36-saltUpgrade py27-saltUpgrade py37-saltUpgrade py32-saltUpgrade py34-saltUpgrade py35-salt | Oct 28, 2018 | Oct 27, 2018 |
| Suse | — | Upgrade salt-sshUpgrade salt-minionUpgrade salt-masterUpgrade salt-cloudUpgrade salt-zsh-completionUpgrade salt-bash-completionUpgrade salt-docUpgrade saltUpgrade salt-apiUpgrade python2-saltUpgrade salt-proxyUpgrade salt-standalone-formulas-configurationUpgrade python2-distroUpgrade salt-syndicUpgrade salt-transactional-updateUpgrade python3-distroUpgrade salt-fish-completionUpgrade python3-salt | Nov 20, 2018 | Oct 24, 2018 |
| Ubuntu | — | Upgrade salt-cloud (Ubuntu Pro)Upgrade salt-masterUpgrade salt-syndic (Ubuntu Pro)Upgrade salt-proxy (Ubuntu Pro)Upgrade salt-common (Ubuntu Pro)Upgrade salt-minionUpgrade salt-apiUpgrade salt-master (Ubuntu Pro)Upgrade salt-commonUpgrade salt-ssh (Ubuntu Pro)Upgrade salt-minion (Ubuntu Pro)Upgrade salt-api (Ubuntu Pro) | Aug 15, 2020 | Oct 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub