296,748
Total vulnerabilities in the database
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
| Software | From | Fixed in |
|---|---|---|
| saltstack / salt | 2016.11.2 | 2016.11.2.x |
| saltstack / salt | 2016.11.1 | 2016.11.1.x |
| saltstack / salt | 2016.11.0 | 2016.11.0.x |
| saltstack / salt | 2016.11.0-rc2 | 2016.11.0-rc2.x |
| saltstack / salt | 2016.11 | 2016.11.x |
| saltstack / salt | 2016.11.3 | 2016.11.3.x |
| saltstack / salt | 2016.11.0-rc1 | 2016.11.0-rc1.x |