PT-2013-5014 · Saltstack+1 · Salt+1

Published

2013-11-05

·

Updated

2022-05-17

·

CVE-2013-4435

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Salt (aka SaltStack) versions 0.15.0 through 0.17.0
Description The issue allows remote authenticated users who are using external authentication or client ACL to execute restricted routines. This is achieved by embedding the restricted routine in another routine.
Recommendations For Salt (aka SaltStack) versions 0.15.0 through 0.17.0, consider restricting access to routines to prevent unauthorized execution until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1179
CVE-2013-4435
GHSA-V89F-4MC4-H6W9
PYSEC-2013-12

Affected Products

Alt Linux
Salt