VYPR

rpm package

suse/salt&distro=SUSE Linux Enterprise Server 11 SP4-CLIENT-TOOLS

pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLS

Vulnerabilities (23)

  • CVE-2017-12791CriAug 23, 2017
    affected < 2016.11.4-43.7.1fixed 2016.11.4-43.7.1

    Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

  • CVE-2017-8109HigApr 25, 2017
    affected < 2016.11.4-42.2fixed 2016.11.4-42.2

    The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

  • CVE-2016-9639CriFeb 7, 2017
    affected < 2015.8.12-27.1fixed 2015.8.12-27.1

    Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.

Page 2 of 2