In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Aug 22, 2024 | Jan 17, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 17, 2020 |
| Debian | — | Upgrade salt | May 7, 2020 | Jan 17, 2020 |
| Freebsd | — | Upgrade py27-saltUpgrade py38-saltUpgrade py32-saltUpgrade py37-saltUpgrade py33-saltUpgrade py36-saltUpgrade py34-saltUpgrade py35-salt | Mar 7, 2020 | Mar 7, 2020 |
| Suse | — | Upgrade salt-apiUpgrade salt-standalone-formulas-configurationUpgrade salt-minionUpgrade saltUpgrade python3-saltUpgrade salt-zsh-completionUpgrade salt-masterUpgrade salt-cloudUpgrade salt-bash-completionUpgrade salt-sshUpgrade python2-saltUpgrade salt-fish-completionUpgrade salt-proxyUpgrade salt-syndicUpgrade salt-doc | Mar 11, 2020 | Jan 17, 2020 |
| Ubuntu | — | Upgrade salt-commonUpgrade salt-apiUpgrade salt-masterUpgrade salt-minion | Aug 15, 2020 | Jan 17, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub