187
VMScore

CVE-2017-8109

Published: 25/04/2017 Updated: 05/05/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The salt-ssh minion code in SaltStack Salt 2016.11 prior to 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt 2016.11.2

saltstack salt 2016.11.0

saltstack salt 2016.11

saltstack salt 2016.11.1

saltstack salt 2016.11.3

Vendor Advisories

Debian Bug report logs - #861219 salt: CVE-2017-8109 Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 26 Apr 2017 05:39:01 UTC Severity: important Tags: fixed-upstream, patch, security, upstream Fo ...
The salt-ssh minion code in SaltStack Salt 201611 before 2016114 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients) ...