CVE-2019-17361
critical · 9.8In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
9.8
CVSS
15.2%
EPSS (exploit prob.)
97th
EPSS percentile
2020-01-17
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| saltstack | salt | <= 2019.2.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| opensuse | leap | 15.1 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00026.html
- https://docs.saltstack.com/en/latest/topics/releases/2019.2.3.html#security-fix
- https://github.com/saltstack/salt/commits/master
- https://usn.ubuntu.com/4459-1/
- https://www.debian.org/security/2020/dsa-4676
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00026.html
- https://docs.saltstack.com/en/latest/topics/releases/2019.2.3.html#security-fix
- https://github.com/saltstack/salt/commits/master
- https://usn.ubuntu.com/4459-1/
- https://www.debian.org/security/2020/dsa-4676
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-17361