← Back

CVE-2020-25592

nvd nist
Published: Nov 6, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

Affected (16)

1 product
Salt
1 product
Debian Linux
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Saltstack
Before 2015.8.10
From 2015.8.11 to 2015.8.13
From 2016.11.0 to 2016.11.3
From 2016.11.4 to 2016.11.6
From 2016.11.7 to 2016.11.10
From 2016.3.0 to 2016.3.4
From 2016.3.5 to 2016.3.6
From 2016.3.7 to 2016.3.8
From 2017.5.0 to 2017.7.4
From 2017.7.5 to 2017.7.8
From 2018.2.0 to 2018.3.5
From 2019.2.0 to 2019.2.5
From 3000.0 to 3000.3
Version 3001
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0

References (16)

Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.