Podatność CVE-2020-16846


Publikacja: 2020-11-06

Opis:
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
High
SaltStack Salt REST API Arbitrary Command Execution
wvu
13.11.2020

Typ:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

 Referencje:
https://github.com/saltstack/salt/releases
https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/

Copyright 2024, cxsecurity.com

 

Back to Top