Skip to content

SaltStack MITM SSH attack in salt-ssh

High severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated May 1, 2024

Package

pip salt (pip)

Affected versions

= 0.17.0

Patched versions

0.17.1

Description

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

References

Published by the National Vulnerability Database Nov 5, 2013
Published to the GitHub Advisory Database May 17, 2022
Reviewed May 1, 2024
Last updated May 1, 2024

Severity

High

Weaknesses

CVE ID

CVE-2013-4436

GHSA ID

GHSA-f22j-37jj-cxw9

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.