CVE-2019-1010259 is a critical SQL Injection vulnerability affecting SaltStack Salt versions 2018.3 and 2019.2. Specifically, the mysql.user_chpass function within the MySQL module is susceptible to specially crafted password strings. This allows an unauthenticated attacker to escalate privileges on a MySQL server deployed by a cloud provider, ultimately leading to Remote Code Execution (RCE). The vulnerability has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 78/100 indicates its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:saltstack:salt_2018:3.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:saltstack:salt_2019:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.