Get a Pentest and security assessment of your IT network.

Cyber Security

SaltStack reveals new critical vulnerabilities, patch now

SaltStack, a VMware-owned company, has revealed critical vulnerabilities impacting Salt versions 3002 and prior, with patches available as of today. Salt is an open-source IT infrastructure management solution written in Python that is widely used by data centers around the world. The three vulnerabilities disclosed today are as follows, with their severity mentioned in the parentheses: CVE-2020-16846 (High/Critical) is a shell injection vulnerability in Salt API that was patched by removing the `shell=True` option when calling “subprocess.call”” via the SSH client.”

Source: https://www.bleepingcomputer.com/news/security/saltstack-reveals-new-critical-vulnerabilities-patch-now/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security