Known vulnerabilities in Salt 3001 - page 2

Vendor: SaltStack
Software: Salt
Version: 3001
Software CPE: cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
Total vulnerabilities: 30
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Salt version 3001 Salt 3001 is affected by 30 vulnerabilities: 4 high, 12 medium, 14 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU50986 - Improper Authentication
CVE-2021-3144
CWE-287 High
No
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 28 more
#VU50985 - Improper Certificate Validation
CVE-2020-35662
CWE-295 Medium
No
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50984 - Command injection
CVE-2021-3148
CWE-77 Medium
No
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50983 - Information Exposure Through Log Files
CVE-2021-25284
CWE-532 Low
No
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50982 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-25283
CWE-94 High
No
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50981 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-3197
CWE-78 High
No
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50980 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-25282
CWE-22 Medium
Public exploit available
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU48204 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-16846
CWE-78 Medium
Public exploit available
Exploited
2019.2.6, 2019.2.7, 3000.4, 3000.5, 3001.2, 3001.3, 3002.1 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 9 more
#VU48205 - Incorrect Default Permissions
CVE-2020-17490
CWE-276 Low
No
No
2019.2.6, 2019.2.7, 3000.4, 3000.5, 3001.2, 3001.3, 3002.1 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 8 more
#VU48206 - Improper Authentication
CVE-2020-25592
CWE-287 High
Public exploit available
No
2019.2.6, 2019.2.7, 3000.4, 3000.5, 3001.2, 3001.3, 3002.1 06.11.2020 SB2020110934
SB2020110935
SB2020110936
and 11 more


Showing elements 21 - 40 out of 30