CVE-2013-6617
SaltStack Privilege Escalation vulnerability
7.5
HIGH
CVSS 3.1
EPSS 1.7%
Description
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
How to fix CVE-2013-6617
To remediate CVE-2013-6617, upgrade the affected package to a fixed version below.
Is CVE-2013-6617 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 0.11.0, < 0.17.1
- >= 0.11.0, < 0.17.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |