当前位置:网站首页>Saltstack command injection vulnerability analysis (cve-2020-16846)
Saltstack command injection vulnerability analysis (cve-2020-16846)
2022-07-28 11:56:00 【Thousand miles:)】
0x00 brief introduction
SaltStack It is a centralized management platform for server infrastructure , Configuration management 、 Remote execution 、 Monitoring and other functions , be based on Python Language implementation , Combine lightweight message queuing (ZeroMQ) And Python Third-party module (Pyzmq、PyCrypto、Pyjinjia2、python-msgpack and PyYAML etc. ) structure . By deploying SaltStack, We can execute commands in batches on tens of millions of servers , Configure centralized management according to different businesses 、 Distribute documents 、 Collect server data 、 Operating system foundation and software package management, etc .

0x01 Summary of vulnerability
CVE-2020-16846 and CVE-2020-25592 Combination can be used without authorization salt-api Interface to execute arbitrary commands .CVE-2020-25592 Any user is allowed to call SSH modular ,CVE-2020-16846 Allow users to execute arbitrary commands .
0x02 Affects version
边栏推荐
- Solutions to slow start of MATLAB
- Globalthis is not defined solution
- Four advantages of verification code to ensure mailbox security
- Solutions to the disappearance of Jupiter, spyder, Anaconda prompt and navigator shortcut keys
- Multithreading and high concurrency (III) -- source code analysis AQS principle
- Reflect 机制获取Class 的属性和方法信息
- Today's sleep quality record 74 points
- 业务可视化-让你的流程图'Run'起来(4.实际业务场景测试)
- async await如何实现并发
- 程序的存储态与运行态
猜你喜欢

Three methods of using unity mouse to drive objects

Embrace open source guidelines

Software testing and quality learning notes 1 --- black box testing

Five Ali technical experts have been offered. How many interview questions can you answer

Router firmware decryption idea

Understand how to prevent tampering and hijacking of device fingerprints

Unity遇坑记之 ab包卸载失败

Service workers let the website dynamically load webp pictures

简单选择排序与堆排序

15、用户web层服务(三)
随机推荐
从零开始Blazor Server(2)--整合数据库
Lua对table进行深拷贝
WPF layout controls are scaled up and down with the window, which is suitable for multi-resolution full screen filling applications
Unity 一键替换场景中的物体
Static proxy instance
Detailed explanation of boost official website search engine project
【补题日记】[2022牛客暑期多校2]D-Link with Game Glitch
Five Ali technical experts have been offered. How many interview questions can you answer
Anonymous implementation class object of interface
15. User web layer services (III)
Simple selection sort and heap sort
多线程与高并发(三)—— 源码解析 AQS 原理
What is the process of switching c read / write files from user mode to kernel mode?
Consumer installation and configuration
Specific process of strong cache and negotiation cache
js代码如何被浏览器引擎编译执行的?
Develop your own NPM package from 0
一些多参数函数的具体作用
15、用户web层服务(三)
Upgrading of computing power under the coordination of software and hardware, redefining productivity