Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 PyPI

SaltStack Salt arbitrary command execution in Salt-api via ssh_client

GHSA-8r7r-x48r-pf8f · CVE-2017-5200 · PYSEC-2017-39

Published · Modified

Description

Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.

Ready to move

Start Securing

Free, no credit card | First findings in minutes