First published: Tue Jun 25 2024(Updated: )
It was discovered that Salt incorrectly validated method calls and sanitized paths. A remote attacker could possibly use this issue to access some methods without authentication. (CVE-2020-11651, CVE-2020-11652)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/salt-common | <0.17.5+ds-1ubuntu0.1~esm2 | 0.17.5+ds-1ubuntu0.1~esm2 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/salt-master | <0.17.5+ds-1ubuntu0.1~esm2 | 0.17.5+ds-1ubuntu0.1~esm2 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/salt-minion | <0.17.5+ds-1ubuntu0.1~esm2 | 0.17.5+ds-1ubuntu0.1~esm2 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.