In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-01-17T01:16:29
Updated: 2024-08-05T01:40:15.336Z
Reserved: 2019-10-08T00:00:00
Link: CVE-2019-17361
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-01-17T02:15:11.493
Modified: 2024-11-21T04:32:10.850
Link: CVE-2019-17361
Redhat