Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
2016-04-12T14:59:09.087
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | saltstack | salt | 2015.8.0 | Yes |
Application | saltstack | salt | 2015.8.1 | Yes |
Application | saltstack | salt | 2015.8.2 | Yes |
Application | saltstack | salt | 2015.8.3 | Yes |
Operating System | opensuse | leap | 42.1 | Yes |