Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2015-6918

Disclosure Date: October 10, 2017 (last updated November 26, 2024)
salt before 2015.5.5 leaks git usernames and passwords to the log.
0
Attacker Value
Unknown

CVE-2015-6941

Disclosure Date: August 09, 2017 (last updated November 26, 2024)
win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.
0
Attacker Value
Unknown

CVE-2016-3176

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
0
Attacker Value
Unknown

CVE-2016-1866

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
0