icon

We found results for “

CVE-2023-34049

Good to know:

icon
icon
icon

Date: November 13, 2024

The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight script before it runs they can ensure Salt-SSH runs their script with the privileges of the user running Salt-SSH. The vulnerability is fixed in versions 3005.4 and 3006.4.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Generation of Predictable Numbers or Identifiers

CWE-340

Top Fix

icon

Upgrade Version

Upgrade to version salt - 3005.4,3006.4

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): HIGH
Privileges Required (PR): LOW
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us