CVE-2013-4438

EUVD-2013-0035
Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors.  NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
saltstacksalt
𝑥
≤ 0.17.0
saltstacksalt
0.6.0
saltstacksalt
0.7.0
saltstacksalt
0.8.0
saltstacksalt
0.8.7
saltstacksalt
0.8.8
saltstacksalt
0.8.9
saltstacksalt
0.9.0
saltstacksalt
0.9.2
saltstacksalt
0.9.3
saltstacksalt
0.9.4
saltstacksalt
0.9.5
saltstacksalt
0.9.6
saltstacksalt
0.9.7
saltstacksalt
0.9.8
saltstacksalt
0.9.9
saltstacksalt
0.10.0
saltstacksalt
0.10.2
saltstacksalt
0.10.3
saltstacksalt
0.10.4
saltstacksalt
0.10.5
saltstacksalt
0.11.0
saltstacksalt
0.12.0
saltstacksalt
0.13.0
saltstacksalt
0.14.0
saltstacksalt
0.15.0
saltstacksalt
0.15.1
saltstacksalt
0.16.0
saltstacksalt
0.16.2
saltstacksalt
0.16.3
saltstacksalt
0.16.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
salt
lucid
dne
precise
dne
quantal
ignored
raring
ignored
saucy
ignored
trusty
not-affected