UBUNTU-CVE-2017-8109
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-8109
Summary:
Details: The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
References: https://ubuntu.com/security/CVE-2017-8109, https://github.com/saltstack/salt/issues/40075, https://github.com/saltstack/salt/pull/40609, https://github.com/saltstack/salt/commit/8492cef7a5c8871a3978ffc2f6e48b3b960e0151, https://bugzilla.suse.com/show_bug.cgi?id=1035912, https://docs.saltstack.com/en/latest/topics/releases/2016.11.4.html, https://github.com/saltstack/salt/pull/40609/commits/6e34c2b5e5e849302af7ccd00509929c3809c658, https://www.cve.org/CVERecord?id=CVE-2017-8109
Affected packages
Package
Name: salt
Purl: pkg:deb/ubuntu/[email protected]+dfsg1-1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
