SUSE-SU-2018:3813-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3813-1
SUSE-SU-2018:3813-1
Summary: Security update for salt
Details: This update for salt fixes the following issues: Salt was updated to version 2016.11.10 and contains the following fixes: Security issues fixed: - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api (bsc#1113698). - CVE-2018-15751: Fixed remote authentication bypass in salt-api(netapi) that allows to execute arbitrary commands (bsc#1113699).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183813-1/, https://bugzilla.suse.com/1113698, https://bugzilla.suse.com/1113699, https://www.suse.com/security/cve/CVE-2018-15750, https://www.suse.com/security/cve/CVE-2018-15751
Affected packages
Package
Name: salt
Purl: pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLS
Affected ranges
Type: ECOSYSTEM
Events:
