PT-2019-20137 · Oracle+1 · Mysql Server+1
Published
2019-07-18
·
Updated
2019-07-18
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
SaltStack Salt versions 2018.3 through 2018.3.3
SaltStack Salt version 2019.2
Description
The issue allows an attacker to escalate privileges on a MySQL server deployed by a cloud provider, leading to remote code execution (RCE). This is achieved through a specially crafted password string, exploiting the
mysql.user chpass function from the MySQL module for Salt.Recommendations
For SaltStack Salt versions 2018.3 through 2018.3.3, update to version 2018.3.4 to resolve the issue.
For SaltStack Salt version 2019.2, update to a version that includes the fix, as the specific fixed version for 2019.2 is not provided.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mysql Server
Saltstack Salt