ZeroHour

CVE-2017-8109

CVSS 3.0
7.8 high
EPSS
<1%p37
Published
()
Modified
Description

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

Vendors
saltstack
Products
salt
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.