CVE-2015-4017: High severity saltstack vulnerability
It was found that Salt does not verify the certificate when connecting via the aliyun, proxmox, and splunk modules.
This flaw has been fixed in version 2014.7.6:
https://groups.google.com/forum/#!topic/salt-users/8Kv1bytGD6c
Other sources
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
— GitHub
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4017?
CVE-2015-4017 is considered a medium severity vulnerability due to the lack of certificate verification.
How do I fix CVE-2015-4017?
To fix CVE-2015-4017, upgrade Salt to version 2014.7.6 or later.
Which versions of Salt are affected by CVE-2015-4017?
CVE-2015-4017 affects Salt version 2014.7.5.
What modules are impacted by CVE-2015-4017?
CVE-2015-4017 impacts the aliyun, proxmox, and splunk modules when connecting.
Is there a workaround for CVE-2015-4017?
No official workaround exists for CVE-2015-4017; upgrading is the recommended solution.