Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-17361
Description:In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-17361
Debian Security Information: DSA-4676 (Google Search)
https://www.debian.org/security/2020/dsa-4676
https://github.com/saltstack/salt/commits/master
SuSE Security Announcement: openSUSE-SU-2020:0357 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00026.html
https://usn.ubuntu.com/4459-1/




© 1998-2025 E-Soft Inc. All rights reserved.