CVE-2017-8109
Dashboard / Vulnerabilities / CVE-2017-8109
CVE-2017-8109
Published: 25 Apr 2017Last Modified: 8 Jul 2026
Summary:
Details: The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
References: http://www.securityfocus.com/bid/98095, https://bugzilla.suse.com/show_bug.cgi?id=1035912, https://docs.saltstack.com/en/latest/topics/releases/2016.11.4.html, https://github.com/saltstack/salt/issues/40075, https://github.com/saltstack/salt/pull/40609, https://github.com/saltstack/salt/pull/40609/commits/6e34c2b5e5e849302af7ccd00509929c3809c658
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- f76dc0f9c06dd0690447a31544b7bd1fe7f5765a
Fixed -None
Affected versions
2016.11
2016.11.0
2016.11.0-rc1
2016.11.0-rc2
2016.11.1
2016.11.2
2016.11.3
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
