Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade salt | Jul 30, 2024 | Apr 12, 2016 |
| Freebsd | — | Upgrade py35-saltUpgrade py34-saltUpgrade py33-saltUpgrade py27-saltUpgrade py32-salt | Dec 10, 2025 | Feb 3, 2016 |
| Suse | — | Upgrade salt-docUpgrade salt-minionUpgrade salt-apiUpgrade salt-proxyUpgrade python2-saltUpgrade salt-sshUpgrade salt-syndicUpgrade salt-standalone-formulas-configurationUpgrade salt-bash-completionUpgrade salt-zsh-completionUpgrade salt-fish-completionUpgrade python3-saltUpgrade saltUpgrade salt-masterUpgrade salt-cloud | Apr 12, 2016 | Apr 12, 2016 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 12, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub