CVE-2020-28243 is a local privilege escalation vulnerability affecting SaltStack Salt versions prior to 3002.5, specifically impacting the minion's restartcheck function through command injection via a crafted process name. This high-severity vulnerability (CVSS 7.8) allows any local user with file creation privileges on the minion to execute arbitrary commands, leading to full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2015.8.10CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | ||
>= 2015.8.11, < 2015.8.13CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | ||
>= 2016.3.0, < 2016.3.4CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | ||
>= 2016.3.5, < 2016.3.6CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | ||
>= 2016.3.7, < 2016.3.8CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.