Security Advisory

CVE-2017-8109

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-04-25 17:00:00
Last updated 2024-08-05 16:27:22
Assigner mitre
State PUBLISHED

Description

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).