<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Salt (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/salt.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/salt-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Salt (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45787 – electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45787</guid>
    <pubDate>Thu, 28 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45787</strong></p>
  <p>electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks. This vuln…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43873 – WWBN AVideo is an open source video platform. In versions up to and including 29...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43873</guid>
    <pubDate>Mon, 11 May 2026 22:22:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43873</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone->myKey, a constant md5($global['systemRootPath'] . $global['salt'])) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to reject non-admin callers without a valid key,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41893 – Signal K Server is a server application that runs on a central hub in a boat. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41893</guid>
    <pubDate>Sat, 09 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41893</strong></p>
  <p>Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default: 100 attempts per 10-minute window, configurable via HTTP_RATE_LIMITS). The WebSocket login path — sending {login: {username, password}} messages over an established WebSocket conn…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4430 – Out-of-bounds write vulnerability in The Document Foundation LibreOffice via cra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4430</guid>
    <pubDate>Thu, 07 May 2026 08:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4430</strong></p>
  <p>Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.  This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5088 – Apache::API::Password versions through 0.5.2 for Perl can generate insecure rand...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5088</guid>
    <pubDate>Wed, 15 Apr 2026 08:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5088</strong></p>
  <p>Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts.  The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to generate random bytes for the salt.  If those modules are unavailable, it will simply return 16 bytes generated with Perl's built-in rand function.  The rand function is unsuitable fo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25726 – Cloudreve is a self-hosted file management and sharing system. Prior to version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25726</guid>
    <pubDate>Fri, 03 Apr 2026 20:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25726</strong></p>
  <p>Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt. These secrets are generated upon first startup and persisted in the database. An attacker can exploit this by obtaining the…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32609 – Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32609</guid>
    <pubDate>Wed, 18 Mar 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32609</strong></p>
  <p>Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenticated configuration secrets exposure on the `/api/v4/config` endpoints by introducing `as_dict_secure()` redaction. However, the `/api/v4/args` and `/api/v4/args/{item}` endpoints were not addressed by this fix. These endpoints return the complete command-line arguments namespac…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30790 – Improper Restriction of Excessive Authentication Attempts, Use of Password Hash ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30790</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30790</strong></p>
  <p>Improper Restriction of Excessive Authentication Attempts, Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Peer authentication, API login modules), rustdesk-server RustDesk Server (OSS) rustdesk-server on Windows, MacOS, Linux (Peer authentication, API login modules) allows Password…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62348 – Salt's junos execution module contained an unsafe YAML decode/load usage. A spec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62348</guid>
    <pubDate>Fri, 30 Jan 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62348</strong></p>
  <p>Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68703 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68703</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68703</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with the same password will have the same derived key. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34433 – AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34433</guid>
    <pubDate>Fri, 19 Dec 2025 16:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34433</strong></p>
  <p>AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installation salt using PHP uniqid(). The installation timestamp is exposed via a public endpoint, and a derived hash identifier is accessible through unauthenticated API responses, allowing attackers to brute-force the remaining entropy. The recovered salt ca…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-40801 – A vulnerability has been identified in COMOS V10.6 (All versions &lt; V10.6.1), COM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40801</guid>
    <pubDate>Tue, 09 Dec 2025 16:17:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-40801</strong></p>
  <p>A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34519 – Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34519</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34519</strong></p>
  <p>Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying a per‑password salt. Because MD5 is a fast, unsalted hash, an attacker who obtains the password database can efficiently perform offline dictionary, rainbow‑table, or brute‑force attacks to recover the original passwo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34208 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34208</guid>
    <pubDate>Thu, 02 Oct 2025 17:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34208</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords using unsalted SHA-512 hashes with a fall-back to unsalted SHA-1. The hashing is performed via PHP's `hash()` function in multiple files (server_write_requests_users.php, update_database.php, legacy/Login.php, tests/Unit/Api/IdpControllerTest.php). No per-user salt is used and th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10205 – Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10205</guid>
    <pubDate>Wed, 17 Sep 2025 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10205</strong></p>
  <p>Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-759</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32874 – An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32874</guid>
    <pubDate>Wed, 16 Jul 2025 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32874</strong></p>
  <p>An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A vulnerability exists in the EncryptionUtil class because symmetric encryption is implemented in a deterministic and non-randomized fashion. The method Encrypt(byte[] clearData) derives both the encryption key and the IV from a fixed, hardcoded input by using a static salt value. As a result, identical plainte…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7504 – The Friends plugin for WordPress is vulnerable to PHP Object Injection in versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7504</guid>
    <pubDate>Sat, 12 Jul 2025 09:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7504</strong></p>
  <p>The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52101 – linjiashop &lt;=0.9 is vulnerable to Incorrect Access Control. When using the defau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52101</guid>
    <pubDate>Tue, 01 Jul 2025 21:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52101</strong></p>
  <p>linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and "salt". The password can then be obtained through brute-force cracking.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-44203 – In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44203</guid>
    <pubDate>Fri, 20 Jun 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-44203</strong></p>
  <p>In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22239 – Arbitrary event injection on Salt Master. The master's "_minion_event" method ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22239</guid>
    <pubDate>Fri, 13 Jun 2025 07:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22239</strong></p>
  <p>Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13951 – One way hash with predictable salt vulnerabilities in ASPECT may expose sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13951</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13951</strong></p>
  <p>One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-760</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3426 – We observed that Intellispace Portal binaries doesn’t have any protection mechan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3426</guid>
    <pubDate>Mon, 07 Apr 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3426</strong></p>
  <p>We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer the application to gain insights into its internal workings, which can potentially lead to the disco…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49094 – In the Linux kernel, the following vulnerability has been resolved:

net/tls: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49094</guid>
    <pubDate>Wed, 26 Feb 2025 07:00:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49094</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/tls: fix slab-out-of-bounds bug in decrypt_internal  The memory size of tls_ctx->rx.iv for AES128-CCM is 12 setting in tls_set_sw_offload(). The return value of crypto_aead_ivsize() for "ccm(aes)" is 16. So memcpy() require 16 bytes from 12 bytes memory space will trigger slab-out-of-bounds bug as following:  ===============…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51478 – YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak crypt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51478</guid>
    <pubDate>Thu, 31 Oct 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51478</strong></p>
  <p>YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22232 – A specially crafted url can be created which leads to a directory traversal in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22232</guid>
    <pubDate>Thu, 27 Jun 2024 07:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22232</strong></p>
  <p>A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36496 – The configuration file is encrypted with a static key derived from a 
static fiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36496</guid>
    <pubDate>Mon, 24 Jun 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36496</strong></p>
  <p>The configuration file is encrypted with a static key derived from a  static five-character password which allows an attacker to decrypt this  file. The application hashes this five-character password with  the outdated and broken MD5 algorithm (no salt) and uses the first five  bytes as the key for RC4. The configuration file is then encrypted with  these parameters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24553 – Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24553</guid>
    <pubDate>Mon, 24 Jun 2024 07:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24553</strong></p>
  <p>Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3183 – A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3183</guid>
    <pubDate>Wed, 12 Jun 2024 09:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3183</strong></p>
  <p>A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal key directly. For user principals, this key is a hash of a public per-principal randomly-generated salt and the user’s passw…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49599 – An insufficient entropy vulnerability exists in the salt generation functionalit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49599</guid>
    <pubDate>Wed, 10 Jan 2024 16:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49599</strong></p>
  <p>An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-46900 – Sympa before 6.2.62 relies on a cookie parameter for certain security objectives...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46900</guid>
    <pubDate>Sun, 31 Dec 2023 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-46900</strong></p>
  <p>Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51442 – Navidrome is an open source web-based music collection server and streamer. A se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51442</guid>
    <pubDate>Thu, 21 Dec 2023 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51442</strong></p>
  <p>Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endpoint, allowing for authentication bypass. This exploit enables unauthorized access to any known account by utilizing a JSON Web Token (JWT) signed with the key "not so secret". The vulnerability can only be exploited on instances that have never been…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42443 – Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EV...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42443</guid>
    <pubDate>Mon, 18 Sep 2023 21:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42443</strong></p>
  <p>Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under certain conditions, the memory used by the builtins `raw_call`, `create_from_blueprint` and `create_copy_of` can be corrupted. For `raw_call`, the argument buffer of the call can be corrupted, leading to incorrect `calldata` in the sub-context. For `create_from_blueprint` and `cre…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40173 – Social media skeleton is an uncompleted/framework social media project implement...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40173</guid>
    <pubDate>Fri, 18 Aug 2023 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40173</strong></p>
  <p>Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Social media skeleton did not properly salt passwords leaving user passwords susceptible to cracking should an attacker gain access to hashed passwords. This issue has been addressed in version 1.0.5 and users are advised to upgrade. There are no known w…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26855 – The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26855</guid>
    <pubDate>Tue, 04 Apr 2023 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26855</strong></p>
  <p>The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27580 – CodeIgniter Shield provides authentication and authorization for the CodeIgniter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27580</guid>
    <pubDate>Mon, 13 Mar 2023 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27580</strong></p>
  <p>CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the password storage process. All hashed passwords stored in Shield v1.0.0-beta.3 or earlier are easier to crack than expected due to the vulnerability. Therefore, they should be removed as soon as possible. If an attacker gets (1) the user's hashed password by…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33226 – Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33226</guid>
    <pubDate>Fri, 17 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33226</strong></p>
  <p>Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22599 – InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22599</guid>
    <pubDate>Thu, 12 Jan 2023 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22599</strong></p>
  <p>InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-760: Use of a One-way Hash with a Predictable Salt. They   send MQTT credentials in response to HTTP/HTTPS requests from the cloud platform. These credentials are encoded using a hardcoded string into an MD5 hash. This string could be easily calcul…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-760</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-24649 – The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argumen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-24649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-24649</guid>
    <pubDate>Mon, 21 Nov 2022 11:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-24649</strong></p>
  <p>The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-37710 – Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37710</guid>
    <pubDate>Mon, 07 Nov 2022 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-37710</strong></p>
  <p>Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37164 – Inoda OnTrack v3.4 employs a weak password policy which allows attackers to pote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37164</guid>
    <pubDate>Thu, 08 Sep 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37164</strong></p>
  <p>Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the hashes.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37163 – Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37163</guid>
    <pubDate>Thu, 08 Sep 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37163</strong></p>
  <p>Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the hashes.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22967 – An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 300...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22967</guid>
    <pubDate>Thu, 23 Jun 2022 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22967</strong></p>
  <p>An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3456 – An improper authorization handling flaw was found in Foreman. The Salt plugin fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3456</guid>
    <pubDate>Wed, 30 Mar 2022 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3456</strong></p>
  <p>An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and sys…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22941 – An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 300...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22941</guid>
    <pubDate>Tue, 29 Mar 2022 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22941</strong></p>
  <p>An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configure…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22936 – An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 300...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22936</guid>
    <pubDate>Tue, 29 Mar 2022 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22936</strong></p>
  <p>An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be re-played. A sufficient craft attacker could gain root access on minion under certain scenarios.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22934 – An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 300...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22934</guid>
    <pubDate>Tue, 29 Mar 2022 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22934</strong></p>
  <p>An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-19861 – When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-19861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-19861</guid>
    <pubDate>Fri, 21 Jan 2022 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-19861</strong></p>
  <p>When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_rdf) byte data can be copied, causing heap overflow information leakage.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-19861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35234 – Numerous exposed dangerous functions within Orion Core has allows for read-only ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35234</guid>
    <pubDate>Mon, 20 Dec 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35234</strong></p>
  <p>Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28680 – The devise_masquerade gem before 1.3 allows certain attacks when a password's sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28680</guid>
    <pubDate>Tue, 07 Dec 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28680</strong></p>
  <p>The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side secret_key_base value became publicly known (for instance if it is committed to a public r…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38979 – IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptog...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38979</guid>
    <pubDate>Mon, 15 Nov 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38979</strong></p>
  <p>IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21996 – An issue was discovered in SaltStack Salt before 3003.3. A user who has control ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21996</guid>
    <pubDate>Wed, 08 Sep 2021 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21996</strong></p>
  <p>An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22774 – A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22774</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22774</strong></p>
  <p>A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could lead an attacker to get knowledge of charging station user account credentials using dictionary attacks tec…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36799 – KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt va...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36799</guid>
    <pubDate>Mon, 19 Jul 2021 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36799</strong></p>
  <p>KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32739 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32739</guid>
    <pubDate>Thu, 15 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32739</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user's credentials, an attacker can view most attributes of all config objects including `ticket_…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-18220 – Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-18220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-18220</guid>
    <pubDate>Thu, 20 May 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-18220</strong></p>
  <p>Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-18220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31607 – In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exist...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31607</guid>
    <pubDate>Fri, 23 Apr 2021 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31607</strong></p>
  <p>In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1921 – In the crypt function, we attempt to null terminate a buffer using the size of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1921</guid>
    <pubDate>Wed, 10 Mar 2021 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1921</strong></p>
  <p>In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25315 – CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25315</guid>
    <pubDate>Wed, 03 Mar 2021 10:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25315</strong></p>
  <p>CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE L…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-3197 – An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3197</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-3197</strong></p>
  <p>An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-3148 – An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3148</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-3148</strong></p>
  <p>An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-3144 – In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3144</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-3144</strong></p>
  <p>In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25283 – An issue was discovered in through SaltStack Salt before 3002.5. The jinja rende...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25283</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25283</strong></p>
  <p>An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25282 – An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25282</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25282</strong></p>
  <p>An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25281 – An issue was discovered in through SaltStack Salt before 3002.5. salt-api does n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25281</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25281</strong></p>
  <p>An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35662 – In SaltStack Salt before 3002.5, when authenticating to services using certain m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35662</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35662</strong></p>
  <p>In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28243 – An issue was discovered in SaltStack Salt before 3002.5. The minion's restartche...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28243</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28243</strong></p>
  <p>An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-25592 – In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25592</guid>
    <pubDate>Fri, 06 Nov 2020 08:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-25592</strong></p>
  <p>In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-16846 – An issue was discovered in SaltStack Salt through 3002. Sending crafted web requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16846</guid>
    <pubDate>Fri, 06 Nov 2020 08:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-16846</strong></p>
  <p>An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9080 – DomainMOD before 4.14.0 uses MD5 without a salt for password storage.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9080</guid>
    <pubDate>Tue, 20 Oct 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9080</strong></p>
  <p>DomainMOD before 4.14.0 uses MD5 without a salt for password storage.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-16244 – GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calcul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16244</guid>
    <pubDate>Wed, 23 Sep 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-16244</strong></p>
  <p>GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform at high risk because an authenticated user can retrieve all user account data and then retrieve the actual passwords.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-759</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-8028 – A Improper Access Control vulnerability in the configuration of salt of SUSE Lin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8028</guid>
    <pubDate>Thu, 17 Sep 2020 10:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-8028</strong></p>
  <p>A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch Server 4.0, SUSE Manager Server 3.2, SUSE Manager Server 4.0 allows local users to escalate to root on every system managed by SUSE manager. On the managing node itself code can be executed as user salt, potentially al…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11651 – An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11651</guid>
    <pubDate>Thu, 30 Apr 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11651</strong></p>
  <p>An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18897 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18897</guid>
    <pubDate>Mon, 02 Mar 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18897</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 20…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9449 – An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, Bl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9449</guid>
    <pubDate>Fri, 28 Feb 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9449</strong></p>
  <p>An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (client) version 19.11 allows an attacker (with a guest or user session cookie) to escalate privileges by retrieving the cookie salt value and creating a valid session cookie for an arbitrary user or admin.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5229 – Opencast before 8.1 stores passwords using the rather outdated and cryptographic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5229</guid>
    <pubDate>Thu, 30 Jan 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5229</strong></p>
  <p>Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthermore, the hashes are salted using the username instead of a random salt, causing hashes for users with the same username and password to collide which is problematic especially for popular users like the default `admin` user. This essentially means that for an attacker, it migh…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17361 – In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client ena...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17361</guid>
    <pubDate>Fri, 17 Jan 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17361</strong></p>
  <p>In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-1010259 – SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1010259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1010259</guid>
    <pubDate>Thu, 18 Jul 2019 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-1010259</strong></p>
  <p>SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3916 – Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) fir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3916</guid>
    <pubDate>Thu, 11 Apr 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3916</strong></p>
  <p>Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API URL in a web browser (e.g. /api).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3907 – Premisys Identicard version 3.1.190 stores user credentials and other sensitive ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3907</guid>
    <pubDate>Fri, 18 Jan 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3907</strong></p>
  <p>Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-0030 – Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for tri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0030</guid>
    <pubDate>Tue, 15 Jan 2019 21:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-0030</strong></p>
  <p>Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file contents. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15751 – SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15751</guid>
    <pubDate>Wed, 24 Oct 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15751</strong></p>
  <p>SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14647 – Python's elementtree C accelerator failed to initialise Expat's hash salt during...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14647</guid>
    <pubDate>Tue, 25 Sep 2018 00:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14647</strong></p>
  <p>Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-335</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15681 – An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their passw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15681</guid>
    <pubDate>Wed, 05 Sep 2018 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15681</strong></p>
  <p>An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged as HTTPOnly. Due to the weak and predictable salt that is in place, an attacker who successfully steals this cookie can efficiently brute-force it to retrieve the user's cleartext password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9488 – ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9488</guid>
    <pubDate>Tue, 05 Jun 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9488</strong></p>
  <p>ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6619 – Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6619</guid>
    <pubDate>Fri, 11 May 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6619</strong></p>
  <p>Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7893 – In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7893</guid>
    <pubDate>Mon, 23 Apr 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7893</strong></p>
  <p>In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-13701 – An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-13701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-13701</guid>
    <pubDate>Thu, 23 Nov 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-13701</strong></p>
  <p>An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stored without being ciphered with a timestamped ciphering method.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-13701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-14696 – SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-14696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-14696</guid>
    <pubDate>Tue, 24 Oct 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-14696</strong></p>
  <p>SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-14695 – Directory traversal vulnerability in minion id validation in SaltStack Salt befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-14695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-14695</guid>
    <pubDate>Tue, 24 Oct 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-14695</strong></p>
  <p>Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5200 – Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5200</guid>
    <pubDate>Tue, 26 Sep 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5200</strong></p>
  <p>Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5192 – When using the local_batch client from salt-api in SaltStack Salt before 2015.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5192</guid>
    <pubDate>Tue, 26 Sep 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5192</strong></p>
  <p>When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4017 – Salt before 2014.7.6 does not verify certificates when connecting via the aliyun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4017</guid>
    <pubDate>Fri, 25 Aug 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4017</strong></p>
  <p>Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-12791 – Directory traversal vulnerability in minion id validation in SaltStack Salt befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12791</guid>
    <pubDate>Wed, 23 Aug 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-12791</strong></p>
  <p>Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-6941 – win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6941</guid>
    <pubDate>Wed, 09 Aug 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-6941</strong></p>
  <p>win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-534</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-9107 – Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-9107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-9107</guid>
    <pubDate>Fri, 04 Aug 2017 00:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-9107</strong></p>
  <p>Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-9107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-8081 – Poor cryptographic salt initialization in admin/inc/template_functions.php in Ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8081</guid>
    <pubDate>Sun, 30 Apr 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-8081</strong></p>
  <p>Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-8109 – The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8109</guid>
    <pubDate>Tue, 25 Apr 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-8109</strong></p>
  <p>The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9639 – Salt before 2015.8.11 allows deleted minions to read or write to minions with th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9639</guid>
    <pubDate>Tue, 07 Feb 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9639</strong></p>
  <p>Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-5543 – includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5543</guid>
    <pubDate>Fri, 20 Jan 2017 08:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-5543</strong></p>
  <p>includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-1866 – Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the min...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1866</guid>
    <pubDate>Tue, 12 Apr 2016 14:59:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-1866</strong></p>
  <p>Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1866">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
