Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Salt | Saltstack | * | 0.17.0 (including) |
Salt | Saltstack | 0.6.0 (including) | 0.6.0 (including) |
Salt | Saltstack | 0.7.0 (including) | 0.7.0 (including) |
Salt | Saltstack | 0.8.0 (including) | 0.8.0 (including) |
Salt | Saltstack | 0.8.7 (including) | 0.8.7 (including) |
Salt | Saltstack | 0.8.8 (including) | 0.8.8 (including) |
Salt | Saltstack | 0.8.9 (including) | 0.8.9 (including) |
Salt | Saltstack | 0.9.0 (including) | 0.9.0 (including) |
Salt | Saltstack | 0.9.2 (including) | 0.9.2 (including) |
Salt | Saltstack | 0.9.3 (including) | 0.9.3 (including) |
Salt | Saltstack | 0.9.4 (including) | 0.9.4 (including) |
Salt | Saltstack | 0.9.5 (including) | 0.9.5 (including) |
Salt | Saltstack | 0.9.6 (including) | 0.9.6 (including) |
Salt | Saltstack | 0.9.7 (including) | 0.9.7 (including) |
Salt | Saltstack | 0.9.8 (including) | 0.9.8 (including) |
Salt | Saltstack | 0.9.9 (including) | 0.9.9 (including) |
Salt | Saltstack | 0.10.0 (including) | 0.10.0 (including) |
Salt | Saltstack | 0.10.2 (including) | 0.10.2 (including) |
Salt | Saltstack | 0.10.3 (including) | 0.10.3 (including) |
Salt | Saltstack | 0.10.4 (including) | 0.10.4 (including) |
Salt | Saltstack | 0.10.5 (including) | 0.10.5 (including) |
Salt | Saltstack | 0.11.0 (including) | 0.11.0 (including) |
Salt | Saltstack | 0.12.0 (including) | 0.12.0 (including) |
Salt | Saltstack | 0.13.0 (including) | 0.13.0 (including) |
Salt | Saltstack | 0.14.0 (including) | 0.14.0 (including) |
Salt | Saltstack | 0.15.0 (including) | 0.15.0 (including) |
Salt | Saltstack | 0.15.1 (including) | 0.15.1 (including) |
Salt | Saltstack | 0.16.0 (including) | 0.16.0 (including) |
Salt | Saltstack | 0.16.2 (including) | 0.16.2 (including) |
Salt | Saltstack | 0.16.3 (including) | 0.16.3 (including) |
Salt | Saltstack | 0.16.4 (including) | 0.16.4 (including) |
Salt | Ubuntu | quantal | * |
Salt | Ubuntu | raring | * |
Salt | Ubuntu | saucy | * |
Salt | Ubuntu | upstream | * |