Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcx4-5wq7-g5g7

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

SaltStack Salt Information Exposure

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

Пакеты

Наименование

salt

pip
Затронутые версииВерсия исправления

>= 2016.11, < 2016.11.4

2016.11.4

EPSS

Процентиль: 14%
0.00047
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

CVSS3: 5.5
redhat
почти 9 лет назад

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

CVSS3: 7.8
nvd
почти 9 лет назад

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

CVSS3: 7.8
debian
почти 9 лет назад

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 co ...

suse-cvrf
больше 8 лет назад

Security update for Salt

EPSS

Процентиль: 14%
0.00047
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-200