Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
CVE Vulnerabilities
CVE-2015-1839
Published:
Apr 13, 2017
| Modified:
Apr 19, 2017
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
Additional information
NVD
https://nvd.nist.gov/vuln/detail/CVE-2015-1839
CWE
https://cwe.mitre.org/data/definitions/19.html
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
Affected Software
Name
Vendor
Start Version
End Version
Salt
Saltstack
*
2014.7.3
References
https://github.com/saltstack/salt/commit/b49d0d4b5ca5c6f31f03e2caf97cef1088eeed81
https://github.com/saltstack/salt/commit/22d2f7a1ec93300c34e8c42d14ec39d51e610b5c
https://docs.saltstack.com/en/latest/topics/releases/2014.7.4.html
https://bugzilla.redhat.com/show_bug.cgi?id=1212788
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175568.html
Aqua Container Security