When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.
2017-09-26T14:29:00.563
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | saltstack | salt | ≤ 2015.8.12 | Yes |
Application | saltstack | salt | 2016.3.0 | Yes |
Application | saltstack | salt | 2016.3.1 | Yes |
Application | saltstack | salt | 2016.3.2 | Yes |
Application | saltstack | salt | 2016.3.3 | Yes |
Application | saltstack | salt | 2016.3.4 | Yes |
Application | saltstack | salt | 2016.11.0 | Yes |
Application | saltstack | salt | 2016.11.1 | Yes |
Application | saltstack | salt | 2016.11.2 | Yes |