GHSA-v89f-4mc4-h6w9

Suggest an improvement
Source
https://github.com/advisories/GHSA-v89f-4mc4-h6w9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v89f-4mc4-h6w9/GHSA-v89f-4mc4-h6w9.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-v89f-4mc4-h6w9
Aliases
Published
2022-05-17T04:58:26Z
Modified
2024-10-26T22:47:24.675844Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Salt has insufficient argument validation in several modules
Details

Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.

Database specific
{
    "nvd_published_at": "2013-11-05T18:55:00Z",
    "cwe_ids": [
        "CWE-287"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-01T11:19:14Z"
}
References

Affected packages

PyPI / salt

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.15.0
Fixed
0.17.1

Affected versions

0.*

0.15.0
0.15.1
0.15.2
0.15.3
0.15.90
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0rc1
0.17.0

Database specific

{
    "last_known_affected_version_range": "<= 0.17.0"
}