Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-0034 | Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine. |
Github GHSA |
GHSA-v89f-4mc4-h6w9 | Salt has insufficient argument validation in several modules |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-09-17T01:36:05.715Z
Reserved: 2013-06-12T00:00:00Z
Link: CVE-2013-4435
No data.
Status : Deferred
Published: 2013-11-05T18:55:04.807
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-4435
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA