VDB
Sign up
—

PYSEC-2013-13

Quick fix

PYSEC-2013-13 — salt: upgrade to the fixed version with the command below.

pip install --upgrade 'salt>=0.17.1'

Details

Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/salt
Introduced in: 0Fixed in: 0.17.1
Fixpip install --upgrade 'salt>=0.17.1'

References