Search CVE reports
3011 – 3020 of 39004 results
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.
1 affected package
salt
Package | 18.04 LTS |
---|---|
salt | Needs evaluation |
Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.
1 affected package
salt
Package | 18.04 LTS |
---|---|
salt | Needs evaluation |
An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.
1 affected package
salt
Package | 18.04 LTS |
---|---|
salt | Needs evaluation |
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
1 affected package
salt
Package | 18.04 LTS |
---|---|
salt | Needs evaluation |
The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not...
1 affected package
salt
Package | 18.04 LTS |
---|---|
salt | Needs evaluation |
Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
1 affected package
salt
Package | 18.04 LTS |
---|---|
salt | Needs evaluation |
Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.
1 affected package
salt
Package | 18.04 LTS |
---|---|
salt | Needs evaluation |
Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset,...
1 affected package
libspring-java
Package | 18.04 LTS |
---|---|
libspring-java | Needs evaluation |
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of PCSX2 versions up to 2.3.414. Opening a disc image that logs a specially crafted message may allow a...
1 affected package
pcsx2
Package | 18.04 LTS |
---|---|
pcsx2 | Needs evaluation |
go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
1 affected package
golang-gopkg-pg.v5
Package | 18.04 LTS |
---|---|
golang-gopkg-pg.v5 | Needs evaluation |