PT-2019-20137 · Oracle+1 · Mysql Server+1

Publicado

2019-07-18

·

Atualizado

2019-07-18

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions SaltStack Salt versions 2018.3 through 2018.3.3 SaltStack Salt version 2019.2
Description The issue allows an attacker to escalate privileges on a MySQL server deployed by a cloud provider, leading to remote code execution (RCE). This is achieved through a specially crafted password string, exploiting the mysql.user chpass function from the MySQL module for Salt.
Recommendations For SaltStack Salt versions 2018.3 through 2018.3.3, update to version 2018.3.4 to resolve the issue. For SaltStack Salt version 2019.2, update to a version that includes the fix, as the specific fixed version for 2019.2 is not provided.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2019-49

Produtos afetados

Mysql Server
Saltstack Salt