ZeroHour

CVE-2017-5192

CVSS 3.0
8.8 high
EPSS
2%p76
Published
()
Modified
Description

When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.

Vendors
saltstack
Products
salt
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.