CVE-2018-15751
Ubuntu Security Notice USN-4459-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
SaltStack Salt en versiones anteriores a la 2017.7.8 y 2018.3.x en versiones anteriores a la 2018.3.3 permite que los atacantes remotos omitan la autenticación y ejecuten comandos arbitrarios mediante salt-api(netapi).
It was discovered that Salt allows remote attackers to determine which files exist on the server. An attacker could use that to extract sensitive information. It was discovered that Salt has a vulnerability that allows an user to bypass authentication. An attacker could use that to extract sensitive information, execute arbitrary code or crash the server. It was discovered that Salt is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-08-23 CVE Reserved
- 2018-10-24 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://groups.google.com/d/msg/salt-users/L9xqcJ0UXxs/qgDj42obBQAJ | Mailing List | |
https://groups.google.com/d/msg/salt-users/dimVF7rpphY/jn3Xv3MbBQAJ | Mailing List | |
https://lists.debian.org/debian-lts-announce/2020/07/msg00024.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html | 2020-08-20 | |
https://docs.saltstack.com/en/2017.7/topics/releases/2017.7.8.html | 2020-08-20 | |
https://docs.saltstack.com/en/latest/topics/releases/2018.3.3.html | 2020-08-20 | |
https://usn.ubuntu.com/4459-1 | 2020-08-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | < 2017.7.8 Search vendor "Saltstack" for product "Salt" and version " < 2017.7.8" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2018.3.0 < 2018.3.3 Search vendor "Saltstack" for product "Salt" and version " >= 2018.3.0 < 2018.3.3" | - |
Affected
|