Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

SaltStack Salt is vulnerable to shell injection via ProxyCommand argument

GHSA-8rp6-x3r7-5qw3 · CVE-2021-3197 · PYSEC-2021-57

Published · Modified

Description

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes