The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-04-25T17:00:00

Updated: 2024-08-05T16:27:22.195Z

Reserved: 2017-04-25T00:00:00

Link: CVE-2017-8109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-04-25T17:59:00.180

Modified: 2017-05-05T17:58:51.980

Link: CVE-2017-8109

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-04-25T00:00:00Z

Links: CVE-2017-8109 - Bugzilla