HIGH 7.5 PyPI
SaltStack MITM SSH attack in salt-ssh
GHSA-f22j-37jj-cxw9 · CVE-2013-4436 · PYSEC-2013-26
Published · Modified
Description
The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2013-4436
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2013-26.yaml
- PACKAGE https://github.com/saltstack/salt
- WEB http://docs.saltstack.com/topics/releases/0.17.1.html
- WEB http://www.openwall.com/lists/oss-security/2013/10/18/3
Ready to move
Start Securing
Free, no credit card | First findings in minutes