Описание
Salt vulnerable to Improper Certificate Validation
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-4017
- https://bugzilla.redhat.com/show_bug.cgi?id=1222960
- https://docs.saltstack.com/en/latest/topics/releases/2014.7.6.html
- https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2017-31.yaml
- https://groups.google.com/forum/#!topic/salt-users/8Kv1bytGD6c
- http://www.openwall.com/lists/oss-security/2015/05/19/2
Пакеты
Наименование
salt
pip
Затронутые версииВерсия исправления
< 2014.7.6
2014.7.6
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 8 лет назад
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
redhat
почти 11 лет назад
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
CVSS3: 7.5
nvd
больше 8 лет назад
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
CVSS3: 7.5
debian
больше 8 лет назад
Salt before 2014.7.6 does not verify certificates when connecting via ...