Known vulnerabilities in salt (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:salt_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 18
Public exploits: 7
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting salt (Debian package) salt (Debian package) is affected by 18 known vulnerabilities: 1 critical, 5 high, 8 medium, 4 low Critical High Medium Low

Vulnerabilities (18)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU58294 -
CVE-2021-21996
Low
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 23.11.2021 SB2021112301
SB2021112302
SB2021102724
and 20 more
#VU58292 - Command injection
CVE-2021-31607
CWE-77 Low
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 23.11.2021 SB2021042332
SB2021112302
SB2021052114
and 24 more
#VU50988 - Permissions, Privileges, and Access Controls
CVE-2020-28243
CWE-264 Medium
Available
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50987 - Improper Certificate Validation
CVE-2020-28972
CWE-295 Medium
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50986 - Improper Authentication
CVE-2021-3144
CWE-287 High
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 28 more
#VU50985 - Improper Certificate Validation
CVE-2020-35662
CWE-295 Medium
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50984 - Command injection
CVE-2021-3148
CWE-77 Medium
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50983 - Information Exposure Through Log Files
CVE-2021-25284
CWE-532 Low
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50982 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-25283
CWE-94 High
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50981 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-3197
CWE-78 High
No
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50980 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-25282
CWE-22 Medium
Available
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50979 - Improper Access Control
CVE-2021-25281
CWE-284 Medium
Available
No
2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU48204 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-16846
CWE-78 Medium
Available
Exploited
2018.3.4+dfsg1-6+deb10u2 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 9 more
#VU48205 - Incorrect Default Permissions
CVE-2020-17490
CWE-276 Low
No
No
2018.3.4+dfsg1-6+deb10u2 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 8 more
#VU48206 - Improper Authentication
CVE-2020-25592
CWE-287 High
Available
No
2018.3.4+dfsg1-6+deb10u2 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 11 more
#VU27599 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-17361
CWE-78 High
No
No
2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1 07.05.2020 SB2020011714
SB2020050705
SB2020020730
and 2 more
#VU27495 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-11652
CWE-22 Medium
Available
Exploited
2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1 04.05.2020 SB2020050410
SB2020050417
SB2020050506
and 10 more
#VU27494 - Improper Authentication
CVE-2020-11651
CWE-287 Critical
Available
Exploited
2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1 04.05.2020 SB2020050410
SB2020050417
SB2020050506
and 10 more