CVE-2013-4438
CVE-2013-4438 is a high-severity vulnerability in Saltstack Salt with a CVSS 2.0 base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 2% (80th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Saltstack Salt
- Published:
- Last modified:
Description
Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.
Frequently asked questions
- What is CVE-2013-4438?
- Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.
- How severe is CVE-2013-4438?
- CVE-2013-4438 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2013-4438 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (80th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2013-4438?
- CVE-2013-4438 primarily affects Saltstack Salt. In total, 31 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2013-4438?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2013-4438 published?
- CVE-2013-4438 was published on 2013-11-05 and last updated on 2026-06-16.
References
- http://docs.saltstack.com/topics/releases/0.17.1.html
- http://www.openwall.com/lists/oss-security/2013/10/18/3
Affected products (31)
- cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.8.7:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.8.8:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.8.9:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.4:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.8:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.9.9:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.10.2:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.10.3:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.10.4:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.10.5:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.13.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.15.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.15.1:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.16.0:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.16.2:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.16.3:*:*:*:*:*:*:*
- cpe:2.3:a:saltstack:salt:0.16.4:*:*:*:*:*:*:*
More vulnerabilities in Saltstack Salt
- CVE-2013-6617 — Critical (CVSS 10.0): The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it…
- CVE-2013-4437 — Critical (CVSS 10.0): Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to…
- CVE-2021-33226 — Critical (CVSS 9.8): Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func…
- CVE-2021-25315 — Critical (CVSS 9.8): CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed…
- CVE-2021-3197 — Critical (CVSS 9.8): An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection…
- CVE-2021-3148 — Critical (CVSS 9.8): An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in…
All CVEs affecting Saltstack Salt →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…