Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
CVSS Details
- CVSS 3.0 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade salt | Jul 30, 2024 | Feb 7, 2017 |
| Suse | — | Upgrade salt-fish-completionUpgrade saltUpgrade spacewalk-backend-libsUpgrade salt-bash-completionUpgrade python3-saltUpgrade supportutils-plugin-susemanager-clientUpgrade salt-zsh-completionUpgrade osadUpgrade salt-sshUpgrade salt-docUpgrade salt-standalone-formulas-configurationUpgrade python2-saltUpgrade salt-syndicUpgrade salt-apiUpgrade salt-minionUpgrade salt-masterUpgrade salt-cloudUpgrade osa-commonUpgrade salt-proxy | Apr 24, 2018 | Feb 7, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub