Known vulnerabilities in Salt - page 3

Vendor: SaltStack
Software: Salt
Software CPE: cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
Total vulnerabilities: 60
Public exploits: 7
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Salt Salt is affected by 60 known vulnerabilities: 1 critical, 9 high, 20 medium, 30 low Critical High Medium Low

Vulnerabilities (60)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU27599 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-17361
CWE-78 High
No
No
2019.2.3 07.05.2020 SB2020011714
SB2020050705
SB2020020730
and 2 more
#VU27494 - Improper Authentication
CVE-2020-11651
CWE-287 Critical
Available
Exploited
2019.2.4, 3000.2 04.05.2020 SB2020050410
SB2020050417
SB2020050506
and 10 more
#VU15545 - Command injection
CVE-2018-15751
CWE-77 Low
No
No
2017.7.8, 2018.3.3 26.10.2018 SB2018102608
SB2018121816
SB2018122002
and 6 more
#VU15544 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-15750
CWE-22 Low
No
No
2017.7.8, 2018.3.3 25.10.2018 SB2018102608
SB2018121816
SB2018122002
and 6 more
#VU12737 - Command injection
CVE-2017-5200
CWE-77 Low
No
No
- 15.05.2018 SB2017100217
SB2017020212
SB2017013113
#VU12736 - Improper input validation
CVE-2017-14696
CWE-20 Low
No
No
- 15.05.2018 SB2017100217
SB2017100907
#VU12735 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2017-14695
CWE-22 Low
No
No
- 15.05.2018 SB2017100217
SB2017100907
#VU12734 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2017-12791
CWE-22 Low
No
No
- 15.05.2018 SB2017100217
SB2017082313
SB2017082603
#VU12733 - Improper Access Control
CVE-2016-9639
CWE-284 Low
No
No
- 15.05.2018 SB2017100217
#VU12278 - Permissions, Privileges, and Access Controls
CVE-2017-7893
CWE-264 Low
No
No
- 27.04.2018 SB2017032206
#VU32162 - Improper Authentication
CVE-2017-5192
CWE-287 High
No
No
2015.8.13, 2016.3.5, 2016.11.2 26.09.2017 SB2017092618
SB2017020211
SB2017013113
#VU38423 - Improper Certificate Validation
CVE-2015-4017
CWE-295 Medium
No
No
- 25.08.2017 SB2017082510
#VU39104 - Exposure of sensitive information to an unauthorized actor
CVE-2017-8109
CWE-200 Low
No
No
- 25.04.2017 SB2017042515
#VU39762 - Improper Authentication
CVE-2016-3176
CWE-287 Medium
No
No
- 31.01.2017 SB2017013106
#VU42394 - Permissions, Privileges, and Access Controls
CVE-2013-6617
CWE-264 High
No
No
- 05.11.2013 SB2013110505
SB2013101701
SB2013101702
#VU42395 - Permissions, Privileges, and Access Controls
CVE-2013-4439
CWE-264 Low
No
No
- 05.11.2013 SB2013110505
SB2013101701
SB2013101702
#VU42396 - Improper Authentication
CVE-2013-4435
CWE-287 Low
No
No
- 05.11.2013 SB2013110505
SB2013101701
SB2013101702
#VU42397 - Improper input validation
CVE-2013-4436
CWE-20 High
No
No
- 05.11.2013 SB2013110505
SB2013101701
SB2013101702
#VU42398 - Improper input validation
CVE-2013-4437
CWE-20 High
No
No
- 05.11.2013 SB2013110505
SB2013101701
SB2013101702
#VU42399 - Improper Control of Generation of Code ('Code Injection')
CVE-2013-4438
CWE-94 Medium
No
No
- 05.11.2013 SB2013110506
SB2013101701
SB2013101702


Showing elements 41 - 60 out of 60