Back

CRITICAL

salt: Remote command execution and incorrect access control when using salt-api

Published Oct 24, 2018

Description

SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).

Affected products

Remediation

No remediation recorded yet.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 24, 2018
Updated Aug 5, 2024
Reserved Aug 23, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Oct 25, 2018
GHSA-X549-R7M8-GV63