CVE-2017-8109: Infoleak
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.4 - Upgrade
Upgrade
SaltStack Salt (salt-ssh minion code)to a version that resolves this vulnerability.Fixed in 2016.11.4
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8109?
CVE-2017-8109 is classified as a moderate severity vulnerability due to potential credential leakage.
How do I fix CVE-2017-8109?
To fix CVE-2017-8109, upgrade SaltStack Salt to version 2016.11.4 or later.
What systems are affected by CVE-2017-8109?
CVE-2017-8109 affects SaltStack Salt versions 2016.11 through 2016.11.3.
What type of vulnerability is CVE-2017-8109?
CVE-2017-8109 is a configuration permission issue that can expose sensitive credentials.
Can CVE-2017-8109 be exploited remotely?
No, CVE-2017-8109 requires local access to the affected systems to exploit the vulnerability.