VDB
CVE-2017-8109
CVE-2017-8109
REJECTED
CVSS 7.800000190734863 HIGH
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
EPSS 0.43% · 36.4th percentile
Risk Scores
CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.43%
36.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | salt | 0, 2016.11.8+dfsg1-1, 2017.7.3+dfsg1-1 |
Timeline
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Mar 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Jan 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-8109 third-party-advisory
- https://github.com/saltstack/salt/issues/40075 third-party-advisory
- https://github.com/saltstack/salt/pull/40609 third-party-advisory
- https://github.com/saltstack/salt/commit/8492cef7a5c8871a3978ffc2f6e48b3b960e0151 third-party-advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1035912 third-party-advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.4.html third-party-advisory
- https://github.com/saltstack/salt/pull/40609/commits/6e34c2b5e5e849302af7ccd00509929c3809c658 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-8109 third-party-advisory