CVE-2020-25592 PUBLISHED

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

EPSS 44.94% · 97.6th percentile

Risk Scores

EPSS Score
44.94%
97.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSsalt0, 2015.8.8+ds-1ubuntu0.1+esm1, 2015.8.8+ds-1ubuntu0.1
Ubuntu:22.04:LTSsalt3004.1+dfsg-2, 0, 3002.6+dfsg1-4
Ubuntu:Pro:18.04:LTSsalt2016.11.5+ds-1, 2016.11.8+dfsg1-1, 2017.7.2+dfsg1-2ubuntu1
Ubuntu:Pro:14.04:LTSsalt0.17.5+ds-1ubuntu0.1~esm1, 0.17.5+ds-1, 0.17.5-1

Timeline

References

Open in Interactive Console →