SaltStack Salt 2016.11.x before 2016.11.10, 2017.7.x before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
{
"cwe_ids": [
"CWE-287"
],
"nvd_published_at": "2018-10-24T22:29:00Z",
"github_reviewed_at": "2024-04-22T22:21:19Z",
"github_reviewed": true,
"severity": "CRITICAL"
}