2.1
CVSSv2

CVE-2015-8034

Published: 30/01/2017 Updated: 02/03/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The state.sls function in Salt prior to 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file.

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt

Vendor Advisories

Debian Bug report logs - #807356 salt: CVE-2015-8034: Saving statesls cache data to disk with insecure permissions Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 7 Dec 2015 20:45:01 UTC Severity ...
The statesls function in Salt before 201583 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file ...