PT-2013-5014 · Saltstack+1 · Salt+1

Publicado

2013-11-05

·

Atualizado

2022-05-17

·

CVE-2013-4435

CVSS v4.0

7.7

Alta

VetorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Salt (aka SaltStack) versions 0.15.0 through 0.17.0
Description The issue allows remote authenticated users who are using external authentication or client ACL to execute restricted routines. This is achieved by embedding the restricted routine in another routine.
Recommendations For Salt (aka SaltStack) versions 0.15.0 through 0.17.0, consider restricting access to routines to prevent unauthorized execution until a patch is available.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1179
CVE-2013-4435
GHSA-V89F-4MC4-H6W9
PYSEC-2013-12

Produtos afetados

Alt Linux
Salt