CVE-2016-9639
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
02 / AFFECTED SOFTWARE
Affected packages
41 explicit affected versions
108 explicit affected versions
108 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2016/11/25/2
- http://www.openwall.com/lists/oss-security/2016/11/25/3
- http://www.securityfocus.com/bid/94553
- https://docs.saltstack.com/en/2015.8/ref/configuration/master.html#rotate-aes-key
- https://github.com/advisories/GHSA-hvmj-356c-gpf4
- https://docs.saltproject.io/en/latest/topics/releases/2015.8.11.html#new-master-configuration-parameter
- https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2017-34.yaml
- https://github.com/saltstack/salt
- https://nvd.nist.gov/vuln/detail/CVE-2016-9639
- https://web.archive.org/web/20200227212146/http://www.securityfocus.com/bid/94553