CVE Vulnerabilities

CVE-2017-5192

Improper Authentication

Published: Sep 26, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
SaltSaltstack*2015.8.12 (including)
SaltSaltstack2016.3.0 (including)2016.3.0 (including)
SaltSaltstack2016.3.1 (including)2016.3.1 (including)
SaltSaltstack2016.3.2 (including)2016.3.2 (including)
SaltSaltstack2016.3.3 (including)2016.3.3 (including)
SaltSaltstack2016.3.4 (including)2016.3.4 (including)
SaltSaltstack2016.11.0 (including)2016.11.0 (including)
SaltSaltstack2016.11.1 (including)2016.11.1 (including)
SaltSaltstack2016.11.2 (including)2016.11.2 (including)
SaltUbuntuartful*
SaltUbuntuesm-apps/xenial*
SaltUbuntuesm-infra-legacy/trusty*
SaltUbuntutrusty*
SaltUbuntutrusty/esm*
SaltUbuntuupstream*
SaltUbuntuxenial*
SaltUbuntuyakkety*
SaltUbuntuzesty*

Potential Mitigations

References