CVE Vulnerabilities

CVE-2017-5192

Improper Authentication

Published: Sep 26, 2017 | Modified: Oct 06, 2017
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Salt Saltstack * 2015.8.12 (including)
Salt Saltstack 2016.3.0 (including) 2016.3.0 (including)
Salt Saltstack 2016.3.1 (including) 2016.3.1 (including)
Salt Saltstack 2016.3.2 (including) 2016.3.2 (including)
Salt Saltstack 2016.3.3 (including) 2016.3.3 (including)
Salt Saltstack 2016.3.4 (including) 2016.3.4 (including)
Salt Saltstack 2016.11.0 (including) 2016.11.0 (including)
Salt Saltstack 2016.11.1 (including) 2016.11.1 (including)
Salt Saltstack 2016.11.2 (including) 2016.11.2 (including)
Salt Ubuntu artful *
Salt Ubuntu esm-apps/xenial *
Salt Ubuntu esm-infra-legacy/trusty *
Salt Ubuntu trusty *
Salt Ubuntu trusty/esm *
Salt Ubuntu upstream *
Salt Ubuntu xenial *
Salt Ubuntu yakkety *
Salt Ubuntu zesty *

Potential Mitigations

References