Search CVE reports


Toggle filters

51 – 60 of 71 results


CVE-2017-5192

Medium priority
Vulnerable

When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to...

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Not affected
Show less packages

CVE-2017-14696

Medium priority

Some fixes available 2 of 4

SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not affected Not in release Not affected
Show less packages

CVE-2017-14695

Medium priority

Some fixes available 2 of 4

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via...

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not affected Not in release Not affected
Show less packages

CVE-2017-12791

Medium priority

Some fixes available 2 of 4

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not affected Not in release Not affected
Show less packages

CVE-2016-9639

Medium priority
Vulnerable

Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Not affected
Show less packages

CVE-2016-3176

High priority
Vulnerable

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Not affected
Show less packages

CVE-2016-1866

Medium priority
Vulnerable

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Not affected
Show less packages

CVE-2015-8034

High priority
Vulnerable

The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not affected Not in release Not affected
Show less packages

CVE-2015-6941

Medium priority

Some fixes available 1 of 3

win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not affected
Show less packages

CVE-2015-6918

Medium priority

Some fixes available 1 of 6

salt before 2015.5.5 leaks git usernames and passwords to the log.

1 affected package

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not affected
Show less packages