
We found results for “”
CVE-2020-35662
Good to know:


Date: February 26, 2021
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. After conducting further research, Mend has determined that versions v0.6.0--v3000.6, v3001rc1--v3001.4 and v3002rc1--v3002.2 of Salt are vulnerable to CVE-2020-35662.
Language: Python
Severity Score
Related Resources (22)
Severity Score
Weakness Type (CWE)
Improper Certificate Validation
CWE-295Top Fix

Upgrade Version
Upgrade to version salt - 3001.5;salt - 3002.3;salt - 2015.8.13;salt - 2016.11.5;salt - 2016.11.10;salt - 2017.7.8;salt - 2019.2.8;salt - 3000.7
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | NONE |
Additional information: |