VYPR
High severity7.8NVD Advisory· Published Apr 25, 2017· Updated Jun 17, 2026

CVE-2017-8109

CVE-2017-8109

Description

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
saltPyPI
>= 2016.11, < 2016.11.42016.11.4

Affected products

17

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.