CVE-2013-4438

Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors.  NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
saltstacksalt
𝑥
≤ 0.17.0
saltstacksalt
0.6.0
saltstacksalt
0.7.0
saltstacksalt
0.8.0
saltstacksalt
0.8.7
saltstacksalt
0.8.8
saltstacksalt
0.8.9
saltstacksalt
0.9.0
saltstacksalt
0.9.2
saltstacksalt
0.9.3
saltstacksalt
0.9.4
saltstacksalt
0.9.5
saltstacksalt
0.9.6
saltstacksalt
0.9.7
saltstacksalt
0.9.8
saltstacksalt
0.9.9
saltstacksalt
0.10.0
saltstacksalt
0.10.2
saltstacksalt
0.10.3
saltstacksalt
0.10.4
saltstacksalt
0.10.5
saltstacksalt
0.11.0
saltstacksalt
0.12.0
saltstacksalt
0.13.0
saltstacksalt
0.14.0
saltstacksalt
0.15.0
saltstacksalt
0.15.1
saltstacksalt
0.16.0
saltstacksalt
0.16.2
saltstacksalt
0.16.3
saltstacksalt
0.16.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
salt
trusty
not-affected
saucy
ignored
raring
ignored
quantal
ignored
precise
dne
lucid
dne