CVE Vulnerabilities

CVE-2013-6617

Published: Nov 05, 2013 | Modified: Nov 06, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.

Affected Software

Name Vendor Start Version End Version
Salt Saltstack 0.11.0 (including) 0.11.0 (including)
Salt Saltstack 0.12.0 (including) 0.12.0 (including)
Salt Saltstack 0.13.0 (including) 0.13.0 (including)
Salt Saltstack 0.14.0 (including) 0.14.0 (including)
Salt Saltstack 0.15.0 (including) 0.15.0 (including)
Salt Saltstack 0.15.1 (including) 0.15.1 (including)
Salt Saltstack 0.16.0 (including) 0.16.0 (including)
Salt Saltstack 0.16.2 (including) 0.16.2 (including)
Salt Saltstack 0.16.3 (including) 0.16.3 (including)
Salt Saltstack 0.16.4 (including) 0.16.4 (including)
Salt Saltstack 0.17.0 (including) 0.17.0 (including)

References