An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
| Software | From | Fixed in |
|---|---|---|
| saltstack / salt | 3001 | 3001.x |
| saltstack / salt | 2019.2.0 | 2019.2.5 |
| saltstack / salt | 3000.0 | 3000.3 |
| saltstack / salt | 2018.2.0 | 2018.3.5 |
| saltstack / salt | 2016.3.7 | 2016.3.8 |
| saltstack / salt | 2017.7.5 | 2017.7.8 |
| saltstack / salt | 2017.5.0 | 2017.7.4 |
| saltstack / salt | 2016.11.7 | 2016.11.10 |
| saltstack / salt | 2016.11.4 | 2016.11.6 |
| saltstack / salt | 2016.11.0 | 2016.11.3 |
| saltstack / salt | 2016.3.5 | 2016.3.6 |
| saltstack / salt | 2015.8.11 | 2015.8.13 |
| saltstack / salt | 2016.3.0 | 2016.3.4 |
| saltstack / salt | - | 2015.8.10 |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
| saltstack / salt | 3002 | 3002.x |
| fedoraproject / fedora | 31 | 31.x |
| opensuse / leap | 15.1 | 15.1.x |