CVE-2013-4438: Code Injection
Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4438?
CVE-2013-4438 is classified as a potential security risk due to its ability to allow remote attackers to execute arbitrary YAML code.
How do I fix CVE-2013-4438?
To address CVE-2013-4438, upgrade SaltStack to version 0.17.1 or later.
What versions of SaltStack are affected by CVE-2013-4438?
CVE-2013-4438 affects SaltStack versions prior to 0.17.1, including versions 0.6.0 through 0.16.4.
What type of attack can CVE-2013-4438 facilitate?
CVE-2013-4438 can facilitate remote code execution through unsafe processing of YAML files.
Is CVE-2013-4438 confirmed as a vulnerability by the vendor?
The vendor has stated that CVE-2013-4438 may not be a vulnerability as the YAML to be loaded is considered safe.