Back to search
CVE-2020-28243
Published: Feb 27, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2021-904a2dbc0c
vendor-advisory
FEDORA-2021-5756fbf8a6
vendor-advisory
FEDORA-2021-43eb5584ad
vendor-advisory
GLSA-202103-01
vendor-advisory
DSA-5011
vendor-advisory
GLSA-202310-22
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now