SaltStack Salt Multiple Security Bypass and Command Injection Vulnerabilities
BID:60868
CVE-2013-2228 |Info
SaltStack Salt Multiple Security Bypass and Command Injection Vulnerabilities
| Bugtraq ID: | 60868 |
| Class: | Unknown |
| CVE: |
CVE-2013-2228 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2013 12:00AM |
| Updated: | Jul 01 2013 12:00AM |
| Credit: | Ronald Volgers |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SaltStack Salt Multiple Security Bypass and Command Injection Vulnerabilities
Salt is prone to multiple security-bypass vulnerabilities and a command-injection vulnerability.
Exploiting these issues could allow an attacker to bypass certain security restrictions or execute arbitrary commands in the context of the application.
Salt is prone to multiple security-bypass vulnerabilities and a command-injection vulnerability.
Exploiting these issues could allow an attacker to bypass certain security restrictions or execute arbitrary commands in the context of the application.
Exploit / POC
SaltStack Salt Multiple Security Bypass and Command Injection Vulnerabilities
An attacker can exploit these issues using readily available tools.
An attacker can exploit these issues using readily available tools.
Solution / Fix
SaltStack Salt Multiple Security Bypass and Command Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SaltStack Salt Multiple Security Bypass and Command Injection Vulnerabilities
References:
References: