CVE-2019-1010259

CWE-89SQL Injection5 documents4 sources
Severity
9.8CRITICAL
EPSS
0.4%
top 41.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 24

Description

SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

CVEListV5saltstack/salt2018.3, 2019.2 [fixed: 2018.3.4]
PyPIsalt2018.3.02018.3.4+1

Patches

🔴Vulnerability Details

4
OSV
SaltStack Salt SQL Injection vulnerability in mysql.user_chpass function2022-05-24
GHSA
SaltStack Salt SQL Injection vulnerability in mysql.user_chpass function2022-05-24
OSV
CVE-2019-1010259: SaltStack Salt 20182019-07-18
CVEList
CVE-2019-1010259: SaltStack Salt 20182019-07-18