Known vulnerabilities in salt (Debian package)
Vendor:
Debian
Software:
salt (Debian package)
Software CPE:
cpe:2.3:o:debian:salt_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
18
Public exploits:
7
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2016.11.2+ds-1+deb9u5
2016.11.2+ds-1+deb9u6
2016.11.2+ds-1+deb9u7
2016.11.2+ds-1+deb9u8
2016.11.2+ds-1+deb9u9
2016.11.2+ds-1+deb9u10
3002.5+dfsg1-1
3002.6+dfsg1-1
3002.6+dfsg1-2
3002.6+dfsg1-3
3002.6+dfsg1-4
3002.7+dfsg1-1
3004+dfsg1-1
3004+dfsg1-2
3004+dfsg1-3
3004+dfsg1-4
3004+dfsg1-5
3004+dfsg1-6
3004+dfsg1-7
3004+dfsg1-8
3004+dfsg1-9
3004+dfsg1-10
3004.1+dfsg-1
3004.1+dfsg-2
3004.1+dfsg-2.1
3004.1+dfsg-2.2
3002.6+dfsg1-4+deb11u1
2018.3.4+dfsg1-6+deb10u3
2018.3.4+dfsg1-6+deb10u2
3002.2+dfsg1
3002.2+dfsg1-1
3002.1+dfsg1
3002.1+dfsg1-1
3002+dfsg1
3002+dfsg1-1
3001.1+dfsg1-2
3001.1+dfsg1
3001.1+dfsg1-1
3001+dfsg1
3001+dfsg1-2
3001+dfsg1-1
2014.1.13+ds-3+deb8u1
2016.11.2+ds-1+deb9u4
3000+dfsg1-4
2016.11.2+ds-1+deb9u3
2018.3.4+dfsg1-6+deb10u1
3000.2+dfsg1-1
3000.1+dfsg1
3000+dfsg1
2018.3.4+dfsg1
2016.11.2+ds
2014.1.13+ds
3000.1+dfsg1-1
3000+dfsg1-3
3000+dfsg1-2
3000+dfsg1-1
2019.2.3+dfsg1-2
2019.2.3+dfsg1-1
2018.3.4+dfsg1-7
2018.3.4+dfsg1-6
2018.3.4+dfsg1-5
2018.3.4+dfsg1-4
2018.3.4+dfsg1-3
2018.3.4+dfsg1-2
2018.3.4+dfsg1-1
2018.3.4~git20180207+dfsg1-1
2018.3.3+dfsg1-2
2018.3.3+dfsg1-1
0.10.1-2~bpo60+1
0.10.1-2~bpo60+2
0.10.1-3~bpo60+1
0.15.1-1~bpo60+1
0.15.1-1~bpo70+1
0.16.4-2~bpo70+1
2014.1.10+ds-2
2016.3.0+ds-1~bpo8+1
2016.3.2+ds-1~bpo8+1
2016.3.3+ds-3~bpo8+1
2016.3.4+ds-2~bpo8+1
2016.11.1+ds-1~bpo8+1
2016.11.2+ds-1+deb9u2
2017.7.4+dfsg1-1
2017.7.3+dfsg1-1
2017.7.2+dfsg1-2
2017.7.2+dfsg1-1
2016.11.8+dfsg1-2
2016.11.8+dfsg1-1
2016.11.2+ds-1+deb9u1
2016.11.5+ds-1
0.17.5+ds-1~bpo70+1
2014.1.13+ds-2
2014.1.13+ds-3
2014.7.4+ds-1
2014.7.5+ds-1
2015.5.0+ds-1
2015.5.2+ds-1
2015.5.3+ds-1
2015.8.1+ds-1
2015.8.1+ds-2
2015.8.3+ds-1
2015.8.3+ds-2
2015.8.3+ds-3
2015.8.5+ds-1
2015.8.7+ds-1
2015.8.8+ds-1
2016.3.0+ds-1
2016.3.1+ds-1
2016.3.2+ds-1
2016.3.3+ds-1
2016.3.3+ds-2
2016.3.3+ds-3
2016.3.4+ds-1
2016.3.4+ds-2
2016.11.1+ds-1
2016.11.2+ds-1
2016.11.2+ds-1~bpo8+1
0.9.9-1
0.10.0-1
0.10.1-1
0.10.1-2
0.10.1-3
0.10.2-1~experimental+1
0.10.4-1
0.10.5-1
0.11.1-1
0.11.1+ds-1
0.12.0-1
0.12.1-1
0.12.1-1~bpo60+1~madduck.1
0.12.1-1~bpo60+1~madduck.2
0.14.0-1
0.14.1-1
0.15.1-1
0.15.3-1
0.16.0-1
0.16.2-1
0.16.2-2
0.16.3-1
0.16.4-1
0.16.4-2
0.17.0-1
0.17.0-2
0.17.1+dfsg-1
0.17.2-1
0.17.2-2
0.17.2-3
0.17.4-1
0.17.4-2
0.17.5-1
0.17.5+ds-1
2014.1.0+ds-1
2014.1.1+ds-1
2014.1.3+ds-1
2014.1.3+ds-2
2014.1.4+ds-1
2014.1.4+ds-2
2014.1.5+ds-1
2014.1.5+ds-2
2014.1.5+ds-3
2014.1.5+ds-4
2014.1.5+ds-5
2014.1.6+ds-1
2014.1.7+ds-1
2014.1.7+ds-2
2014.1.10+ds-1
2014.1.11+ds-1
2014.1.11+ds-2
2014.1.13+ds-1
2014.7.0+ds-1
2014.7.0+ds-2
2014.7.1+ds-1
2014.7.1+ds-2
2014.7.1+ds-3
2014.7.2+ds-1
Vulnerabilities (18)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU58294 - CVE-2021-21996 |
Low | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 23.11.2021 |
SB2021112301 SB2021112302 SB2021102724 and 20 more |
|||
| #VU58292 - Command injection CVE-2021-31607 |
CWE-77 | Low | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 23.11.2021 |
SB2021042332 SB2021112302 SB2021052114 and 24 more |
||
| #VU50988 - Permissions, Privileges, and Access Controls CVE-2020-28243 |
CWE-264 | Medium | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50987 - Improper Certificate Validation CVE-2020-28972 |
CWE-295 | Medium | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50986 - Improper Authentication CVE-2021-3144 |
CWE-287 | High | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 28 more |
||
| #VU50985 - Improper Certificate Validation CVE-2020-35662 |
CWE-295 | Medium | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50984 - Command injection CVE-2021-3148 |
CWE-77 | Medium | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50983 - Information Exposure Through Log Files CVE-2021-25284 |
CWE-532 | Low | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50982 - Improper Control of Generation of Code ('Code Injection') CVE-2021-25283 |
CWE-94 | High | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50981 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-3197 |
CWE-78 | High | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50980 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-25282 |
CWE-22 | Medium | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50979 - Improper Access Control CVE-2021-25281 |
CWE-284 | Medium | 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU48204 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2020-16846 |
CWE-78 | Medium | 2018.3.4+dfsg1-6+deb10u2 | 06.11.2020 |
SB2020110934 SB2020110935 SB2020110936 and 9 more |
||
| #VU48205 - Incorrect Default Permissions CVE-2020-17490 |
CWE-276 | Low | 2018.3.4+dfsg1-6+deb10u2 | 06.11.2020 |
SB2020110934 SB2020110935 SB2020110936 and 8 more |
||
| #VU48206 - Improper Authentication CVE-2020-25592 |
CWE-287 | High | 2018.3.4+dfsg1-6+deb10u2 | 06.11.2020 |
SB2020110934 SB2020110935 SB2020110936 and 11 more |
||
| #VU27599 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2019-17361 |
CWE-78 | High | 2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1 | 07.05.2020 |
SB2020011714 SB2020050705 SB2020020730 and 2 more |
||
| #VU27495 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-11652 |
CWE-22 | Medium | 2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1 | 04.05.2020 |
SB2020050410 SB2020050417 SB2020050506 and 10 more |
||
| #VU27494 - Improper Authentication CVE-2020-11651 |
CWE-287 | Critical | 2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1 | 04.05.2020 |
SB2020050410 SB2020050417 SB2020050506 and 10 more |