CVE-2015-6941: Infoleak
A vulnerability in winuseradd, salt-cloud and Linode driver were found:
winuseradd returned data including the password of the newly created user salt-cloud debug output contained winpassword and sudopassword authentication credentials Linode driver displayed authentication credentials in debug logs
Upstream patch:
https://github.com/twangboy/salt/commit/c0689e32154c41f59840ae10ffc5fbfa30618710
External reference:
https://docs.saltstack.com/en/latest/topics/releases/2015.8.1.html https://docs.saltstack.com/en/latest/topics/releases/2015.5.6.html
Other sources
winuseradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6941?
CVE-2015-6941 is considered a high-severity vulnerability due to the exposure of sensitive user credentials.
How do I fix CVE-2015-6941?
To fix CVE-2015-6941, upgrade to the patched versions 2015.5.6 or 2015.8.1 of Salt or later.
Which versions of Salt are affected by CVE-2015-6941?
CVE-2015-6941 affects Salt versions from 5.0 to 5.5 and also 8.0.
What types of data are exposed in CVE-2015-6941?
CVE-2015-6941 exposes sensitive data such as the passwords of newly created users and authentication credentials.
Is there a specific package manager recommended for resolving CVE-2015-6941?
Yes, using package managers like pip or Red Hat's package manager is recommended to obtain the fixes for CVE-2015-6941.