Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
CVSS Details
- CVSS 3.0 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade salt | Jul 30, 2024 | Feb 7, 2017 |
| Suse | — | Upgrade python2-saltUpgrade salt-masterUpgrade salt-cloudUpgrade salt-minionUpgrade salt-syndicUpgrade salt-standalone-formulas-configurationUpgrade salt-apiUpgrade osa-commonUpgrade salt-proxyUpgrade spacewalk-backend-libsUpgrade salt-bash-completionUpgrade salt-fish-completionUpgrade salt-docUpgrade python3-saltUpgrade salt-sshUpgrade saltUpgrade salt-zsh-completionUpgrade supportutils-plugin-susemanager-clientUpgrade osad | Apr 24, 2018 | Feb 7, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub