CVE-2020-28243 vulnerability in SaltStack and Other Products
Published on February 27, 2021
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Products Associated with CVE-2020-28243
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-28243 are published in these products:
Exploit Probability
EPSS
1.73%
Percentile
82.24%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.