Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.6% | — | Saltstack Salt | 24/10/2017 | 17/6/2026 | Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for… | |
| Modificada | Media (6.3) | 1.2% | — | Saltstack Salt 2015 | 10/10/2017 | 17/6/2026 | salt before 2015.5.5 leaks git usernames and passwords to the log. | |
| Modificada | Alta (8.8) | 3.2% | — | Saltstack Salt | 26/9/2017 | 17/6/2026 | Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client. | |
| Modificada | Alta (8.8) | 1.7% | — | Saltstack Salt | 26/9/2017 | 17/6/2026 | When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed. | |
| Modificada | Alta (7.5) | 1.1% | — | Saltstack Salt | 25/8/2017 | 17/6/2026 | Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules. | |
| Modificada | Crítica (9.8) | 4.7% | — | Saltstack Salt | 23/8/2017 | 17/6/2026 | Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. | |
| Modificada | Crítica (9.8) | 2.2% | — | Saltstack Salt 2015 | 9/8/2017 | 17/6/2026 | win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs. | |
| Modificada | Alta (7.8) | 0.43% | — | Saltstack Salt | 25/4/2017 | 17/6/2026 | The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients). | |
| Modificada | Media (5.3) | 0.43% | — | Saltstack SaltFedoraproject Fedora | 13/4/2017 | 17/6/2026 | modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp. | |
| Modificada | Media (5.3) | 0.43% | — | Saltstack SaltFedoraproject Fedora | 13/4/2017 | 17/6/2026 | modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp. | |
| Modificada | Crítica (9.1) | 2.6% | — | Saltstack Salt | 7/2/2017 | 17/6/2026 | Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching. | |
| Modificada | Media (5.6) | 0.87% | — | Saltstack Salt | 31/1/2017 | 17/6/2026 | Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient. | |
| Modificada | Baja (3.3) | 0.41% | — | Saltstack Salt | 30/1/2017 | 17/6/2026 | The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Alta (8.1) | 1.5% | — | Saltstack SaltOpensuse Leap | 12/4/2016 | 17/6/2026 | Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream. | |
| Modificada | Alta (7.2) | 0.41% | — | Saltstack Salt | 22/8/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud. | |
| Modificada | Alta (10) | 3.0% | — | Saltstack Salt | 5/11/2013 | 17/6/2026 | The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges. | |
| Modificada | Media (4.9) | 1.5% | — | Saltstack Salt | 5/11/2013 | 16/6/2026 | Salt (aka SaltStack) before 0.15.0 through 0.17.0 allows remote authenticated minions to impersonate arbitrary minions via a crafted minion with a valid key. | |
| Modificada | Alta (7.5) | 2.1% | — | Saltstack Salt | 5/11/2013 | 16/6/2026 | Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe. | |
| Modificada | Alta (10) | 1.5% | — | Saltstack Salt | 5/11/2013 | 16/6/2026 | Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp." | |
| Modificada | Alta (9.3) | 1.8% | — | Saltstack Salt | 5/11/2013 | 16/6/2026 | The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack. | |
| Modificada | Media (6) | 1.5% | — | Saltstack Salt | 5/11/2013 | 16/6/2026 | Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine. |