Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2017-0123 | Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client. |
![]() |
GHSA-8r7r-x48r-pf8f | SaltStack Salt arbitrary command execution in Salt-api via ssh_client |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T14:55:35.542Z
Reserved: 2017-01-06T00:00:00
Link: CVE-2017-5200

No data.

Status : Deferred
Published: 2017-09-26T14:29:00.597
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-5200


No data.