Back

HIGH

salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client

Published Sep 26, 2017

Description

Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of the salt as shipped with Red Hat Ceph Storage 1.3, Red Hat Ceph Storage 2, and Red Hat Storage Console 2 as salt-api and salt-ssh are not shipped with these products.

Red Hat mitigation

Disable salt-api for mitigation.

Metrics

Weaknesses (0)

No CWE recorded.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 26, 2017
Updated Aug 5, 2024
Reserved Jan 6, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 20, 2017
GHSA-8R7R-X48R-PF8F