3.5
CVSSv2

CVE-2015-6918

Published: 10/10/2017 Updated: 05/11/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.3 | Impact Score: 4 | Exploitability Score: 1.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

salt prior to 2015.5.5 leaks git usernames and passwords to the log.

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt 2015

Vendor Advisories

Debian Bug report logs - #803182 salt: CVE-2015-6918: git module leaks authentication details into log Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 27 Oct 2015 18:39:01 UTC Severity: important T ...
salt before 201555 leaks git usernames and passwords to the log ...