← Back

CVE-2013-4438

nvd nist
Published: Nov 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.

Affected (31)

Products: Saltstack: Salt
1 product
Salt
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Saltstack
Up to 0.17.0
Version 0.10.0
Version 0.10.2
Version 0.10.3
Version 0.10.4
Version 0.10.5
Version 0.11.0
Version 0.12.0
Version 0.13.0
Version 0.14.0
Version 0.15.0
Version 0.15.1
Version 0.16.0
Version 0.16.2
Version 0.16.3
Version 0.16.4
Version 0.6.0
Version 0.7.0
Version 0.8.0
Version 0.8.7
Version 0.8.8
Version 0.8.9
Version 0.9.0
Version 0.9.2
Version 0.9.3
Version 0.9.4
Version 0.9.5
Version 0.9.6
Version 0.9.7
Version 0.9.8
Version 0.9.9

References (4)

Source: secalert@redhat.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.