CVE-2017-8109
25.04.2017, 17:59
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).Enginsight
| Vendor | Product | Version |
|---|---|---|
| saltstack | salt | 2016.11 |
| saltstack | salt | 2016.11.0 |
| saltstack | salt | 2016.11.0:rc1 |
| saltstack | salt | 2016.11.0:rc2 |
| saltstack | salt | 2016.11.1 |
| saltstack | salt | 2016.11.2 |
| saltstack | salt | 2016.11.3 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References