#VU27599 OS Command Injection in Salt - CVE-2019-17361
Published: May 7, 2020
Salt
SaltStack
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation the salt-api NET API with the ssh client enabled. A remote unauthenticated attacker with network access to the API endpoint can pass specially crafted data to the application and execute arbitrary OS commands on the salt-api host.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.