{"id":"GHSA-xcx4-5wq7-g5g7","summary":"SaltStack Salt Information Exposure","details":"The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).","aliases":["CVE-2017-8109","PYSEC-2017-82"],"modified":"2024-10-26T22:48:41.689361Z","published":"2022-05-17T02:46:54Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-22T22:19:53Z","nvd_published_at":"2017-04-25T17:59:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-8109"},{"type":"WEB","url":"https://github.com/saltstack/salt/issues/40075"},{"type":"WEB","url":"https://github.com/saltstack/salt/pull/40609"},{"type":"WEB","url":"https://github.com/saltstack/salt/pull/40609/commits/6e34c2b5e5e849302af7ccd00509929c3809c658"},{"type":"WEB","url":"https://bugzilla.suse.com/show_bug.cgi?id=1035912"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2017-82.yaml"},{"type":"PACKAGE","url":"https://github.com/saltstack/salt"}],"affected":[{"package":{"name":"salt","ecosystem":"PyPI","purl":"pkg:pypi/salt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2016.11"},{"fixed":"2016.11.4"}]}],"versions":["2016.11.0","2016.11.1","2016.11.2","2016.11.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xcx4-5wq7-g5g7/GHSA-xcx4-5wq7-g5g7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}