CVE-2018-15750

Name
CVE-2018-15750
Description
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Release Notes https://groups.google.com/d/msg/salt-users/L9xqcJ0UXxs/qgDj42obBQAJ
Release Notes https://groups.google.com/d/msg/salt-users/dimVF7rpphY/jn3Xv3MbBQAJ
Release Notes https://docs.saltstack.com/en/latest/topics/releases/2018.3.3.html
Release Notes https://docs.saltstack.com/en/2017.7/topics/releases/2017.7.8.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html
MLIST https://lists.debian.org/debian-lts-announce/2020/07/msg00024.html
UBUNTU https://usn.ubuntu.com/4459-1/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* salt >= None < 2017.7.8
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* salt >= 2018.3.0 < 2018.3.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status