Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown
CVE-2015-6941
Disclosure Date: August 09, 2017 (last updated November 26, 2024)
win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.
0
Attacker Value
Unknown
CVE-2017-8109
Disclosure Date: April 25, 2017 (last updated November 26, 2024)
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
0
Attacker Value
Unknown
CVE-2015-1838
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
0
Attacker Value
Unknown
CVE-2015-1839
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
0
Attacker Value
Unknown
CVE-2016-9639
Disclosure Date: February 07, 2017 (last updated November 26, 2024)
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
0
Attacker Value
Unknown
CVE-2016-3176
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
0
Attacker Value
Unknown
CVE-2015-8034
Disclosure Date: January 30, 2017 (last updated November 25, 2024)
The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file.
0
Attacker Value
Unknown
CVE-2016-1866
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
0
Attacker Value
Unknown
CVE-2014-3563
Disclosure Date: August 22, 2014 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.
0
Attacker Value
Unknown
CVE-2013-6617
Disclosure Date: November 05, 2013 (last updated October 05, 2023)
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
0