2023-09-05 12:00:28 +00:00
{
"id" : "CVE-2023-20897" ,
"sourceIdentifier" : "security@vmware.com" ,
"published" : "2023-09-05T11:15:32.973" ,
2025-02-13 19:04:13 +00:00
"lastModified" : "2025-02-13T17:16:02.387" ,
2023-09-14 04:00:29 +00:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-09-05 12:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
2025-02-13 19:04:13 +00:00
"value" : "Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted."
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "Salt masters anteriores a 3005.2 o 3006.2 contienen un DOS en retorno minion. Despu\u00e9s de recibir varios paquetes incorrectos en el servidor de solicitudes igual al n\u00famero de subprocesos de trabajo, el master dejar\u00e1 de responder a las solicitudes de devoluci\u00f3n hasta que se reinicie."
2023-09-05 12:00:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-09-07 20:00:29 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "security@vmware.com" ,
"type" : "Secondary" ,
2023-09-07 20:00:29 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM" ,
2023-09-07 20:00:29 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-09-07 20:00:29 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
} ,
2023-09-05 12:00:28 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-09-05 12:00:28 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM" ,
2023-09-05 12:00:28 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-09-05 12:00:28 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
}
]
} ,
2023-09-07 20:00:29 +00:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-404"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "3005.2" ,
"matchCriteriaId" : "B70F6397-8CB9-47B6-A4BF-C7E4A1017F6A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "3006.0" ,
"versionEndExcluding" : "3006.2" ,
"matchCriteriaId" : "A22FBD43-AC7E-45B9-9EC5-340CF735773E"
}
]
}
]
}
] ,
2023-09-05 12:00:28 +00:00
"references" : [
2023-09-14 04:00:29 +00:00
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OMWJIHQZXHK6FH2E3IWAZCYIRI7FLVOL/" ,
"source" : "security@vmware.com"
} ,
2023-09-05 12:00:28 +00:00
{
"url" : "https://saltproject.io/security-announcements/2023-08-10-advisory/" ,
2023-09-07 20:00:29 +00:00
"source" : "security@vmware.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OMWJIHQZXHK6FH2E3IWAZCYIRI7FLVOL/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://saltproject.io/security-announcements/2023-08-10-advisory/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-09-05 12:00:28 +00:00
}
]
}