Known vulnerabilities in salt (Alpine package)

Software CPE: cpe:2.3:o:alpine:salt_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 11
Public exploits: 4
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting salt (Alpine package) salt (Alpine package) is affected by 11 known vulnerabilities: 1 critical, 3 high, 2 medium, 5 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU48204 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-16846
CWE-78 Medium
Available
Exploited
3002-r1 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 9 more
#VU48205 - Incorrect Default Permissions
CVE-2020-17490
CWE-276 Low
No
No
3002-r1 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 8 more
#VU48206 - Improper Authentication
CVE-2020-25592
CWE-287 High
Available
No
3002-r1 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 11 more
#VU27599 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-17361
CWE-78 High
No
No
3000.1-r2 07.05.2020 SB2020011714
SB2020050705
SB2020020730
and 2 more
#VU27495 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-11652
CWE-22 Medium
Available
Exploited
2019.2.4-r0, 3000.2-r0 04.05.2020 SB2020050410
SB2020050417
SB2020050506
and 10 more
#VU27494 - Improper Authentication
CVE-2020-11651
CWE-287 Critical
Available
Exploited
2019.2.4-r0, 3000.2-r0 04.05.2020 SB2020050410
SB2020050417
SB2020050506
and 10 more
#VU15545 - Command injection
CVE-2018-15751
CWE-77 Low
No
No
2018.3.3-r0 26.10.2018 SB2018102608
SB2018121816
SB2018122002
and 6 more
#VU15544 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-15750
CWE-22 Low
No
No
2018.3.3-r0 25.10.2018 SB2018102608
SB2018121816
SB2018122002
and 6 more
#VU12737 - Command injection
CVE-2017-5200
CWE-77 Low
No
No
2016.11.2-r0 15.05.2018 SB2017100217
SB2017020212
SB2017013113
#VU12734 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2017-12791
CWE-22 Low
No
No
2016.11.7-r0 15.05.2018 SB2017100217
SB2017082313
SB2017082603
#VU32162 - Improper Authentication
CVE-2017-5192
CWE-287 High
No
No
2016.11.2-r0 26.09.2017 SB2017092618
SB2017020211
SB2017013113