Vulnerabilities (CVE)

Filtered by vendor Saltstack Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-4439 1 Saltstack 1 Salt 2013-11-07 4.9 MEDIUM N/A
Salt (aka SaltStack) before 0.15.0 through 0.17.0 allows remote authenticated minions to impersonate arbitrary minions via a crafted minion with a valid key.
CVE-2013-6617 1 Saltstack 1 Salt 2013-11-06 10.0 HIGH N/A
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.