Bug 1090665 - (CVE-2017-7893) VUL-0: CVE-2017-7893: salt: In Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master
(CVE-2017-7893)
VUL-0: CVE-2017-7893: salt: In Salt before 2016.3.6, compromised salt-minions...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Major
: ---
Assigned To: E-Mail List
Security Team bot
https://smash.suse.de/issue/204757/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-04-24 08:17 UTC by Karol Babioch
Modified: 2018-04-24 08:29 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-04-24 08:17:06 UTC
CVE-2017-7893

In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the
salt-master.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7893
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7893
https://docs.saltstack.com/en/2017.7/topics/releases/2016.3.6.html
Comment 1 Klaus Kämpf 2018-04-24 08:29:39 UTC
Salt 2016.11.7 is the currently maintained version.