Improper Authentication in Salt - CVE-2013-4435

 

Improper Authentication in Salt - CVE-2013-4435

Published: November 5, 2013 / Updated: August 10, 2020


Vulnerability identifier: #VU42396
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-4435
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.


Affected software

Salt
Fedora
salt

How to mitigate CVE-2013-4435

Install update from vendor's website.

salt - addressed in versions 0.17.1-1.el5, 0.17.1-1.el6

External References

Related Security Bulletins