SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17361

In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection.

CRITICAL 9.8EPSS 15.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 15.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
15.23% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-77
Affected
saltstack/salt · debian/debian linux · opensuse/leap · canonical/ubuntu linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.