MEDIUM
salt: Directory traversal in salt-api allows remote attackers to identitfy arbitrary files
Published Oct 24, 2018
5.3
MEDIUMCVSS 3.0
EPSS 4.28%
Description
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
Affected products
No data.
No data.
Red Hat Ceph Storage 2
salt
Not affected
Red Hat OpenShift Container Platform 3.10
heketi
Not affected
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.11
cluster-autoscaler
Not affected
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | salt | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | heketi | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | cluster-autoscaler | Not affected | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2018-15750 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1644484 Issue Tracking
- https://docs.saltstack.com/en/2017.7/topics/releases/2017.7.8.html x_refsource_CONFIRMRelease NotesVendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2018.3.3.html x_refsource_CONFIRMRelease NotesVendor Advisory
- https://github.com/advisories/GHSA-jx34-pppm-gjvr Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2018-29.yaml
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2016.11.10.rst#L15
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2017.7.8.rst#L28
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2018.3.3.rst#L58
- https://groups.google.com/d/msg/salt-users/L9xqcJ0UXxs/qgDj42obBQAJ mailing-listx_refsource_MLISTRelease NotesThird Party Advisory
- https://groups.google.com/d/msg/salt-users/dimVF7rpphY/jn3Xv3MbBQAJ mailing-listx_refsource_MLISTRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00024.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-15750
- https://usn.ubuntu.com/4459-1 vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-15750
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 24, 2018
Updated Aug 5, 2024
Reserved Aug 23, 2018
Link CVE-2018-15750
CISA Vulnrichment
GHSA-JX34-PPPM-GJVR Updated n/a