The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-0037 | The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges. |
Github GHSA |
GHSA-7wx3-vr2f-6p29 | SaltStack Privilege Escalation vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://docs.saltstack.com/topics/releases/0.17.1.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T02:02:10.512Z
Reserved: 2013-11-05T00:00:00.000Z
Link: CVE-2013-6617
No data.
Status : Deferred
Published: 2013-11-05T18:55:06.277
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-6617
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA