CVE-2018-15750
MEDIUM5.3EPSS 0.91%salt - security update
Published: 5/13/2022Modified: 3/9/2026
Description
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
Affected packages (3)
- Debian/saltfrom 0, < 2016.11.2+ds-1+deb9u5
- PyPI/salt>= 2017.7.0, < 2017.7.8
- PyPI/saltfrom 0, < 2017.7.8, >= 2018.3.0, < 2018.3.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
References (14)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2018-15750
- PATCHhttps://github.com/saltstack/salt
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html
- WEBhttps://docs.saltstack.com/en/2017.7/topics/releases/2017.7.8.html
- WEBhttps://docs.saltstack.com/en/latest/topics/releases/2018.3.3.html
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2018-29.yaml
- WEBhttps://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2016.11.10.rst#L15
- WEBhttps://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2017.7.8.rst#L28
- WEBhttps://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2018.3.3.rst#L58
- WEBhttps://groups.google.com/d/msg/salt-users/dimVF7rpphY/jn3Xv3MbBQAJ
- WEBhttps://groups.google.com/d/msg/salt-users/L9xqcJ0UXxs/qgDj42obBQAJ
- WEBhttps://lists.debian.org/debian-lts-announce/2020/07/msg00024.html
- WEBhttps://usn.ubuntu.com/4459-1
- WEBhttps://usn.ubuntu.com/4459-1/