CVE-2015-6918: Infoleak
Published Aug 26, 2015
·Updated
It was found that calling git.clone with https user/pass will leak the authentication details to the log.
Upstream patch:
https://github.com/saltstack/salt/commit/28aa9b105804ff433d8f663b2f9b804f2b75495a
Other sources
salt before 2015.5.5 leaks git usernames and passwords to the log.
— Launchpad
Affected Software
4 affected componentsFixes available
redhat/salt<2015.5.5
2015.5.5
debian/salt
pip/salt<2015.5.5
2015.5.5
SaltStack<=5.4
Remediation
Patch Available
Event History
Oct 10, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·12:26 AM
Jan 11, 2024
Data Sourced
via Launchpad·10:21 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·11:59 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-6918?
CVE-2015-6918 is considered a medium severity vulnerability due to the potential exposure of sensitive authentication details.
2
How do I fix CVE-2015-6918?
To remediate CVE-2015-6918, upgrade to salt version 2015.5.6 or later.
3
What does CVE-2015-6918 affect?
CVE-2015-6918 affects versions of the salt package prior to 2015.5.6.
4
Is my system vulnerable to CVE-2015-6918?
If you are running salt version 2015.5.5 or earlier, your system is vulnerable to CVE-2015-6918.
5
What are the consequences of CVE-2015-6918?
CVE-2015-6918 can lead to the unintended leakage of user authentication credentials in log files.