CVE Vulnerabilities

CVE-2017-5200

Published: Sep 26, 2017 | Modified: Oct 03, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salts ssh_client.

Affected Software

Name Vendor Start Version End Version
Salt Saltstack * 2015.8.12 (including)
Salt Saltstack 2016.3.0 (including) 2016.3.0 (including)
Salt Saltstack 2016.3.1 (including) 2016.3.1 (including)
Salt Saltstack 2016.3.2 (including) 2016.3.2 (including)
Salt Saltstack 2016.3.3 (including) 2016.3.3 (including)
Salt Saltstack 2016.3.4 (including) 2016.3.4 (including)
Salt Saltstack 2016.11.0 (including) 2016.11.0 (including)
Salt Saltstack 2016.11.1 (including) 2016.11.1 (including)
Salt Saltstack 2016.11.2 (including) 2016.11.2 (including)

References