The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
| Software | From | Fixed in |
|---|---|---|
| saltstack / salt | 0.17.0 | 0.17.0.x |
| saltstack / salt | 0.14.0 | 0.14.0.x |
| saltstack / salt | 0.16.3 | 0.16.3.x |
| saltstack / salt | 0.15.1 | 0.15.1.x |
| saltstack / salt | 0.16.2 | 0.16.2.x |
| saltstack / salt | 0.11.0 | 0.11.0.x |
| saltstack / salt | 0.16.4 | 0.16.4.x |
| saltstack / salt | 0.15.0 | 0.15.0.x |
| saltstack / salt | 0.13.0 | 0.13.0.x |
| saltstack / salt | 0.16.0 | 0.16.0.x |
| saltstack / salt | 0.12.0 | 0.12.0.x |