Description
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-0033 | Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream. |
Github GHSA |
GHSA-vqh4-crjf-jjxx | Salt Improper Access Control |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T23:10:39.823Z
Reserved: 2016-01-13T00:00:00.000Z
Link: CVE-2016-1866
No data.
Status : Modified
Published: 2016-04-12T14:59:09.087
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-1866
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA