CVE-2018-15750

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.

References

http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html

https://docs.saltstack.com/en/2017.7/topics/releases/2017.7.8.html

https://docs.saltstack.com/en/latest/topics/releases/2018.3.3.html

https://groups.google.com/d/msg/salt-users/dimVF7rpphY/jn3Xv3MbBQAJ

https://groups.google.com/d/msg/salt-users/L9xqcJ0UXxs/qgDj42obBQAJ

https://lists.debian.org/debian-lts-announce/2020/07/msg00024.html

https://usn.ubuntu.com/4459-1/

Details

Source: MITRE

Published: 2018-10-24

Updated: 2020-08-20

Type: CWE-22

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM

Tenable Plugins

View all (12 total)

IDNameProductFamilySeverity
151732openSUSE 15 Security Update : salt (openSUSE-SU-2021:2106-1)NessusSuSE Local Security Checks
critical
151062openSUSE 15 Security Update : salt (openSUSE-SU-2021:0899-1)NessusSuSE Local Security Checks
critical
139659Ubuntu 16.04 LTS / 18.04 LTS : Salt vulnerabilities (USN-4459-1)NessusUbuntu Local Security Checks
critical
139094Debian DLA-2294-1 : salt security updateNessusDebian Local Security Checks
critical
139012openSUSE Security Update : salt (openSUSE-2020-1074)NessusSuSE Local Security Checks
critical
138795SUSE SLED15 / SLES15 Security Update : salt (SUSE-SU-2020:1974-1)NessusSuSE Local Security Checks
critical
123158openSUSE Security Update : salt (openSUSE-2019-1019)NessusSuSE Local Security Checks
critical
120165SUSE SLED15 / SLES15 Security Update : salt (SUSE-SU-2018:3815-1)NessusSuSE Local Security Checks
critical
119805openSUSE Security Update : salt (openSUSE-2018-1574)NessusSuSE Local Security Checks
critical
119759openSUSE Security Update : salt (openSUSE-2018-1569)NessusSuSE Local Security Checks
critical
119115SUSE SLES11 Security Update : salt (SUSE-SU-2018:3813-1)NessusSuSE Local Security Checks
critical
118477FreeBSD : salt -- multiple vulnerabilities (4f7c6af3-6a2c-4ead-8453-04e509688d45)NessusFreeBSD Local Security Checks
critical