In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Aug 22, 2024 | Jan 17, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 17, 2020 |
| Debian | — | Upgrade salt | May 7, 2020 | Jan 17, 2020 |
| Freebsd | — | Upgrade py38-saltUpgrade py27-saltUpgrade py32-saltUpgrade py36-saltUpgrade py33-saltUpgrade py34-saltUpgrade py37-saltUpgrade py35-salt | Mar 7, 2020 | Mar 7, 2020 |
| Suse | — | Upgrade salt-sshUpgrade salt-bash-completionUpgrade salt-syndicUpgrade salt-docUpgrade salt-proxyUpgrade salt-fish-completionUpgrade python2-saltUpgrade salt-minionUpgrade salt-cloudUpgrade python3-saltUpgrade salt-zsh-completionUpgrade salt-apiUpgrade salt-standalone-formulas-configurationUpgrade saltUpgrade salt-master | Mar 11, 2020 | Jan 17, 2020 |
| Ubuntu | — | Upgrade salt-masterUpgrade salt-minionUpgrade salt-apiUpgrade salt-common | Aug 15, 2020 | Jan 17, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub