First published: Tue Feb 07 2017(Updated: )
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SaltStack Salt | <=2015.8.10 | |
pip/salt | <2015.8.11 | 2015.8.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9639 has a medium severity rating due to its potential for unauthorized access.
To resolve CVE-2016-9639, upgrade Salt to version 2015.8.11 or later.
CVE-2016-9639 allows deleted minions to interact with other minions sharing the same ID due to caching issues.
Versions of Salt prior to 2015.8.11 are affected by CVE-2016-9639.
If upgrading is not possible, consider implementing strict access controls to mitigate the risks associated with CVE-2016-9639.