Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3176

Опубликовано: 23 мар. 2016
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.2saltWill not fix
Red Hat Ceph Storage 1.3saltWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1320865salt: insecure configuration of PAM external authentication service

EPSS

Процентиль: 56%
0.00873
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 9 лет назад

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

CVSS3: 5.6
nvd
больше 9 лет назад

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

CVSS3: 5.6
debian
больше 9 лет назад

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external ...

CVSS3: 5.6
github
больше 4 лет назад

Salt Insecure configuration of PAM external authentication service

EPSS

Процентиль: 56%
0.00873
Низкий

6.8 Medium

CVSS2