Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
CVSS Details
- CVSS 3.0 Base Score: 5.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade salt | Jul 30, 2024 | Jan 31, 2017 |
| Freebsd | — | Upgrade py32-saltUpgrade py33-saltUpgrade py34-saltUpgrade py35-saltUpgrade py27-salt | Dec 10, 2025 | Mar 27, 2016 |
| Ubuntu | — | Upgrade salt-minion (Ubuntu Pro)Upgrade salt-master (Ubuntu Pro)Upgrade salt-common (Ubuntu Pro) | Jun 26, 2025 | Jan 31, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub