VDB

PYSEC-2021-57

PYSEC-2021-57 PUBLISHED

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.

Affected Products

VendorProductVersions
PyPIsalt2019.2.6, 0, 2015.8.11

Timeline

  • Feb 27, 2021 CVE Published
  • Apr 22, 2024 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›