#VU15544 Path traversal in Salt - CVE-2018-15750
Published: October 25, 2018 / Updated: October 26, 2018
Salt
SaltStack
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input processed by the salt-api component. A remote attacker can send a query request that submits malicious input, conduct directory traversal attack and determine what files exist on the system, and this information can be used to conduct further attacks.