Known vulnerabilities in Salt 3000 - page 2
Vendor:
SaltStack
Software:
Salt
Version:
3000
Software CPE:
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
Website:
https://saltstack.com/
Total vulnerabilities:
31
Public exploits:
7
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
3008.2
3006.27
3006.26
3008.1
3008.0
3006.25
3007.14
3006.24
3006.23
3006.22
3007.13
3006.21
3007.12
3006.20
3007.11
3006.19
3007.10
3006.18
3007.9
3006.17
3007.8
3006.16
3007.7
3006.15
3007.6
3006.14
3007.5
3006.13
3007.4
3006.12
3007.3
3006.11
3007.2
3006.10
3006.9
3007.1
3006.8
3007.0
3006.7
3006.6
3005.5
3006.5
3006.4
3005.4
3005.3
3006.3
3006.2
3005.2
3006.1
3006.0
3005.1
3005
3002.9
3003.5
3004.2
3004.1
3003.4
3002.8
3004
3001.8
3002.7
3003.3
3003.2
3003.1
3000.9
3001.7
3002.6
3003
3000.7
3001.5
3002.3
3000.8
3001.6
3002.4
3002.5
2019.2.2.2
2019.2.2.3
2019.2.8
3000.6
3001.4
3002.2
2019.2.6
3000.4
3001.2
2019.2.7
3000.5
3001.3
3002.1
3002
3001.1
3001
2019.2.5
3000.3
3000.2
3000.1
3000
2019.8
2019.2.4
2019.2.3
2019.2.2
2019.2.1
2019.2.0
2019.2
2018.11
2018.3.5
2018.3.4
2018.3
2018.2
2017.7
2017.5
2016.11.10
2016.11.9
2016.11
2016.9
2016.3
2015.8.8.2
2015.8
2015.5.11
2015.5.10
2015.5.9
2015.5.8
2015.5.7
2015.5.6
2015.5.5
2015.5.4
2015.5.3
2015.5.2
2015.5.1
2015.5.0
2015.5
2015.2
2014.7.9
2014.7.8
2014.7.7
2014.7.6
2014.7.5
2014.7.4
2014.7.3
2014.7.2
2014.7.1
2014.7.0
2014.7
2014.1.13
2014.1.12
2014.1.11
2014.1.10
2014.1.9
2014.1.8
2014.1.7
2014.1.6
2014.1.5
2014.1.4
2014.1.3
2014.1.2
2014.1.1
2014.1.0
2014.1
0.17.5
0.17.4
0.17.3
0.17.2
0.17.1
0.17.0
0.17
0.16.4
0.16.3
0.16.2
0.16.1
0.16.0
0.16
0.15.90
0.15.3
0.15.2
0.15.1
0.15.0
0.14.1
0.14.0
0.13.3
0.13.2
0.13.1
0.13.0
0.12.1
0.12.0
0.11.1
0.11.0
0.10.5
0.10.4
0.10.3
0.10.2
0.10.1
0.10.0
0.9.9
0.9.8
0.9.7
0.9.6
0.9.5
0.9.4
0.9.3
0.9.2
0.9.1
0.9.0
0.8.9
0.8.8
0.8.7
0.8.0
0.7.0
0.6.0
2018.3.2
2018.3.1
2018.3.0
2017.7.7
2017.7.6
2017.7.5
2017.7.4
2017.7.3
2018.3.3
2017.7.8
2015.8.12
2015.8.13
2016.3.7
2017.7.2
2016.11.8
2016.3.8
2017.7.0
2016.11.0
2016.11.1
2016.11.2
2016.11.3
2016.11.4
2016.11.5
2016.11.6
2017.7.1
2016.11.7
2015.8.0
2015.8.1
2015.8.2
2015.8.3
2015.8.4
2015.8.5
2015.8.6
2015.8.7
2015.8.8
2015.8.9
2015.8.10
2015.8.11
2016.3.6
2016.3.5
2016.3.4
2016.3.3
2016.3.2
2016.3.1
2016.3.0
Vulnerabilities (31)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU50987 - Improper Certificate Validation CVE-2020-28972 |
CWE-295 | Medium | 3000.8, 3001.6, 3002.5 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50986 - Improper Authentication CVE-2021-3144 |
CWE-287 | High | 3000.8, 3001.6, 3002.5 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 28 more |
||
| #VU50985 - Improper Certificate Validation CVE-2020-35662 |
CWE-295 | Medium | 3000.8, 3001.6, 3002.5 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50984 - Command injection CVE-2021-3148 |
CWE-77 | Medium | 3000.8, 3001.6, 3002.5 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50983 - Information Exposure Through Log Files CVE-2021-25284 |
CWE-532 | Low | 3000.8, 3001.6, 3002.5 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU50979 - Improper Access Control CVE-2021-25281 |
CWE-284 | Medium | 3000.8, 3001.6, 3002.5 | 28.02.2021 |
SB2021022809 SB2021022810 SB2021032201 and 29 more |
||
| #VU48204 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2020-16846 |
CWE-78 | Medium | 2019.2.6, 2019.2.7, 3000.4, 3000.5, 3001.2, 3001.3, 3002.1 | 06.11.2020 |
SB2020110934 SB2020110935 SB2020110936 and 9 more |
||
| #VU48205 - Incorrect Default Permissions CVE-2020-17490 |
CWE-276 | Low | 2019.2.6, 2019.2.7, 3000.4, 3000.5, 3001.2, 3001.3, 3002.1 | 06.11.2020 |
SB2020110934 SB2020110935 SB2020110936 and 8 more |
||
| #VU48206 - Improper Authentication CVE-2020-25592 |
CWE-287 | High | 2019.2.6, 2019.2.7, 3000.4, 3000.5, 3001.2, 3001.3, 3002.1 | 06.11.2020 |
SB2020110934 SB2020110935 SB2020110936 and 11 more |
||
| #VU27495 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-11652 |
CWE-22 | Medium | 2019.2.4, 3000.2 | 04.05.2020 |
SB2020050410 SB2020050417 SB2020050506 and 10 more |
||
| #VU27494 - Improper Authentication CVE-2020-11651 |
CWE-287 | Critical | 2019.2.4, 3000.2 | 04.05.2020 |
SB2020050410 SB2020050417 SB2020050506 and 10 more |
Showing elements 21 - 40 out of 31