CVE-2013-4439: Medium severity saltstack vulnerability
Published Nov 5, 2013
·Updated
Salt (aka SaltStack) before 0.15.0 through 0.17.0 allows remote authenticated minions to impersonate arbitrary minions via a crafted minion with a valid key.
Affected Software
8 affected componentsFixes available
pip/salt>=0.15.0<0.17.1
0.17.1
SaltStack Salt=0.15.0
SaltStack Salt=0.15.1
SaltStack Salt=0.16.0
SaltStack Salt=0.16.2
SaltStack Salt=0.16.3
SaltStack Salt=0.16.4
SaltStack Salt=0.17.0
Remediation
Patch Available
Event History
Nov 5, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·04:58 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-4439?
CVE-2013-4439 is categorized as a medium severity vulnerability due to its potential for remote authenticated impersonation.
2
How do I fix CVE-2013-4439?
To mitigate CVE-2013-4439, upgrade SaltStack to version 0.17.1 or later.
3
What versions are affected by CVE-2013-4439?
CVE-2013-4439 affects SaltStack versions from 0.15.0 to 0.17.0.
4
What type of vulnerability is CVE-2013-4439?
CVE-2013-4439 is an impersonation vulnerability that allows remote authenticated minions to masquerade as other minions.
5
Is CVE-2013-4439 exploitable remotely?
Yes, CVE-2013-4439 can be exploited by remote authenticated minions to impersonate arbitrary minions.