VendorsSaltStacksalt3001
Vulnerabilities

SaltStack Salt 3001

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-16846
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
Published 2020-11-06 · Analyzed
9.8KEVEPSS 0.996
CVE-2020-25592
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
Published 2020-11-06 · Modified
9.8EPSS 0.577
CVE-2020-17490
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
Published 2020-11-06 · Modified
5.5EPSS 0.004