Improper Authentication in Salt - CVE-2013-4435
Published: November 5, 2013 / Updated: August 10, 2020
Vulnerability identifier: #VU42396
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-4435
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote #AU# to read and manipulate data.
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.
Affected software
Salt
Fedora
salt
Fedora
salt
How to mitigate CVE-2013-4435
Install update from vendor's website.
salt - addressed in versions 0.17.1-1.el5, 0.17.1-1.el6