Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2015-6918
Disclosure Date: October 10, 2017 (last updated November 26, 2024)
salt before 2015.5.5 leaks git usernames and passwords to the log.
0
Attacker Value
Unknown
CVE-2015-6941
Disclosure Date: August 09, 2017 (last updated November 26, 2024)
win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.
0
Attacker Value
Unknown
CVE-2016-3176
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
0
Attacker Value
Unknown
CVE-2016-1866
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
0