First published: Tue May 19 2015(Updated: )
It was found that Salt does not verify the certificate when connecting via the aliyun, proxmox, and splunk modules. This flaw has been fixed in version 2014.7.6: <a href="https://groups.google.com/forum/#!topic/salt-users/8Kv1bytGD6c">https://groups.google.com/forum/#!topic/salt-users/8Kv1bytGD6c</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SaltStack Salt | =2014.7.5 | |
pip/salt | <2014.7.6 | 2014.7.6 |
=2014.7.5 | ||
redhat/salt | <2014.7.6 | 2014.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4017 is considered a medium severity vulnerability due to the lack of certificate verification.
To fix CVE-2015-4017, upgrade Salt to version 2014.7.6 or later.
CVE-2015-4017 affects Salt version 2014.7.5.
CVE-2015-4017 impacts the aliyun, proxmox, and splunk modules when connecting.
No official workaround exists for CVE-2015-4017; upgrading is the recommended solution.