CVE-2017-8109
Published Apr 25, 2017
Last updated 8 years ago
Overview
- Description
- The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:saltstack:salt:2016.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "689B37E8-7274-4B5A-9419-538A9AB7B99F" }, { "criteria": "cpe:2.3:a:saltstack:salt:2016.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5B7EDF4-414F-429A-BD20-0B967737598C" }, { "criteria": "cpe:2.3:a:saltstack:salt:2016.11.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3D927A3-0450-4C66-9952-0DFD1C8E43F1" }, { "criteria": "cpe:2.3:a:saltstack:salt:2016.11.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D526346-8F23-4016-9D89-7BD4182370A3" }, { "criteria": "cpe:2.3:a:saltstack:salt:2016.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "594339CF-8192-425D-9C8C-AA51342D9477" }, { "criteria": "cpe:2.3:a:saltstack:salt:2016.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E54FADCE-5311-4C8A-9527-1623F9AAC69E" }, { "criteria": "cpe:2.3:a:saltstack:salt:2016.11.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E904BB7-706A-43E0-96CE-2A9E671E4FB3" } ], "operator": "OR" } ] } ]