In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Aug 22, 2024 | Jan 17, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 17, 2020 |
| Debian | — | Upgrade salt | May 7, 2020 | Jan 17, 2020 |
| Freebsd | — | Upgrade py38-saltUpgrade py27-saltUpgrade py32-saltUpgrade py35-saltUpgrade py37-saltUpgrade py33-saltUpgrade py36-saltUpgrade py34-salt | Mar 7, 2020 | Mar 7, 2020 |
| Suse | — | Upgrade saltUpgrade salt-cloudUpgrade salt-minionUpgrade salt-standalone-formulas-configurationUpgrade salt-zsh-completionUpgrade salt-apiUpgrade python3-saltUpgrade salt-masterUpgrade salt-fish-completionUpgrade salt-docUpgrade salt-syndicUpgrade salt-sshUpgrade python2-saltUpgrade salt-proxyUpgrade salt-bash-completion | Mar 11, 2020 | Jan 17, 2020 |
| Ubuntu | — | Upgrade salt-commonUpgrade salt-minionUpgrade salt-masterUpgrade salt-api | Aug 15, 2020 | Jan 17, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub