Описание
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 2017.7.4+dfsg1-1 |
| cosmic | not-affected | 2017.7.4+dfsg1-1 |
| devel | not-affected | 2017.7.4+dfsg1-1 |
| esm-apps/bionic | not-affected | 2017.7.4+dfsg1-1 |
| esm-apps/xenial | not-affected | code not present |
| esm-infra-legacy/trusty | not-affected | code not present |
| precise | DNE | |
| precise/esm | DNE | |
| trusty | not-affected | code not present |
Показывать по
Ссылки на источники
EPSS
2.1 Low
CVSS2
7.8 High
CVSS3
Связанные уязвимости
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 co ...
EPSS
2.1 Low
CVSS2
7.8 High
CVSS3