CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
5.1%
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied
over configuration from the Salt Master without adjusting permissions,
which might leak credentials to local attackers on configured minions
(clients).
bugzilla.suse.com/show_bug.cgi?id=1035912
docs.saltstack.com/en/latest/topics/releases/2016.11.4.html
github.com/saltstack/salt/commit/8492cef7a5c8871a3978ffc2f6e48b3b960e0151
github.com/saltstack/salt/issues/40075
github.com/saltstack/salt/pull/40609
github.com/saltstack/salt/pull/40609/commits/6e34c2b5e5e849302af7ccd00509929c3809c658
launchpad.net/bugs/cve/CVE-2017-8109
nvd.nist.gov/vuln/detail/CVE-2017-8109
security-tracker.debian.org/tracker/CVE-2017-8109
www.cve.org/CVERecord?id=CVE-2017-8109
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
5.1%