Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1866

Опубликовано: 12 апр. 2016
Источник: debian

Описание

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
saltfixed2015.8.5+ds-1package
saltnot-affectedjessiepackage

Примечания

  • https://docs.saltstack.com/en/latest/topics/releases/2015.8.5.html

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

redhat
около 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

CVSS3: 8.1
nvd
почти 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

suse-cvrf
почти 10 лет назад

Security update for salt

CVSS3: 8.1
github
больше 3 лет назад

Salt Improper Access Control