CVE-2017-8109
SaltStack Salt Information Exposure
7.8
HIGH
CVSS 3.1
EPSS 0.05%
Description
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
How to fix CVE-2017-8109
To remediate CVE-2017-8109, upgrade the affected package to a fixed version below.
- PyPI/salt—upgrade to 2016.11.4 or later
- —upgrade to 2016.11.4 or later
Is CVE-2017-8109 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 2016.11, < 2016.11.4
- >= 2016.11, < 2016.11.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |