SB2017042515 - Information disclosure in SaltStack Salt



SB2017042515 - Information disclosure in SaltStack Salt

Published: April 25, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017042515
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2017-8109)

The vulnerability allows a local authenticated user to execute arbitrary code.

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).


Remediation

Install update from vendor's website.