stealthcopter/CVE-2020-28243

stealthcopter/CVE-2020-28243

Releases0
Stars18
CVE-2020-28243 Local Privledge Escalation Exploit in SaltStack Minion

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH4.4 MEDIUM

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.