CVE-2017-7893: Critical severity saltstack vulnerability
Published Apr 23, 2018
·Updated
In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.
Affected Software
2 affected componentsFixes available
pip/salt<2016.3.6
2016.3.6
SaltStack Salt<2016.3.6
Event History
Apr 23, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:47 AM
Frequently Asked Questions
1
What is CVE-2017-7893?
CVE-2017-7893 is a vulnerability in SaltStack Salt before version 2016.3.6 where compromised salt-minions can impersonate the salt-master.
2
What is the severity of CVE-2017-7893?
The severity of CVE-2017-7893 is critical with a score of 9.8.
3
How does CVE-2017-7893 impact SaltStack Salt?
CVE-2017-7893 allows compromised salt-minions to impersonate the salt-master in SaltStack Salt before version 2016.3.6.
4
How can I fix CVE-2017-7893?
To fix CVE-2017-7893, update SaltStack Salt to version 2016.3.6 or higher.
5
Where can I find more information about CVE-2017-7893?
More information about CVE-2017-7893 can be found at the following link: [https://docs.saltstack.com/en/2017.7/topics/releases/2016.3.6.html](https://docs.saltstack.com/en/2017.7/topics/releases/2016.3.6.html).