← All CVEs

CVE-2019-17361

critical · 9.8

In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.

9.8
CVSS
15.2%
EPSS (exploit prob.)
97th
EPSS percentile
2020-01-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
saltstacksalt<= 2019.2.0
debiandebian_linux9.0
debiandebian_linux10.0
opensuseleap15.1
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-17361