Total vulnerabilities in the database
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
Software | From | Fixed in |
---|---|---|
saltstack / salt | 2015.8.1 | 2015.8.1.x |
saltstack / salt | 2015.8.2 | 2015.8.2.x |
saltstack / salt | 2015.8.3 | 2015.8.3.x |
saltstack / salt | 2015.8.0 | 2015.8.0.x |
opensuse / leap | 42.1 | 42.1.x |