CVE Vulnerabilities

CVE-2015-6941

DEPRECATED: Information Exposure Through Debug Log Files

Published: Aug 09, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5.5 MODERATE
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.

Weakness

This entry has been deprecated because its abstraction was too low-level. See CWE-532.

Affected Software

NameVendorStart VersionEnd Version
Salt_2015Saltstack5.0 (including)5.0 (including)
Salt_2015Saltstack5.1 (including)5.1 (including)
Salt_2015Saltstack5.2 (including)5.2 (including)
Salt_2015Saltstack5.3 (including)5.3 (including)
Salt_2015Saltstack5.4 (including)5.4 (including)
Salt_2015Saltstack5.5 (including)5.5 (including)
Salt_2015Saltstack8.0 (including)8.0 (including)
SaltUbuntuesm-infra-legacy/trusty*
SaltUbuntutrusty*
SaltUbuntutrusty/esm*
SaltUbuntuupstream*
SaltUbuntuvivid*
SaltUbuntuwily*

References