Skip to content

SaltStack Salt Information Exposure

High severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated Apr 22, 2024

Package

pip salt (pip)

Affected versions

>= 2016.11, < 2016.11.4

Patched versions

2016.11.4

Description

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

References

Published by the National Vulnerability Database Apr 25, 2017
Published to the GitHub Advisory Database May 17, 2022
Last updated Apr 22, 2024
Reviewed Apr 22, 2024

Severity

High
7.8
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CVE ID

CVE-2017-8109

GHSA ID

GHSA-xcx4-5wq7-g5g7

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.