CVE-2020-28243: Debian Linux
High severity, CVSS 7.8. EPSS: 4.3% chance of exploitation in the next 30 days.
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only; version 11.0 only
- Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
- SaltStack Salt: before 2015.8.10 (fixed in 2015.8.10); from 2015.8.11, before 2015.8.13 (fixed in 2015.8.13); from 2016.3.0, before 2016.3.4 (fixed in 2016.3.4); from 2016.3.5, before 2016.3.6 (fixed in 2016.3.6); from 2016.3.7, before 2016.3.8 (fixed in 2016.3.8); from 2016.3.9, before 2016.11.3 (fixed in 2016.11.3); …
Published 2021-02-27. Last modified 2026-06-17.