8.1

CVE-2016-1866

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Saltstack ≫ Salt Version 2015.8.0
Saltstack ≫ Salt Version 2015.8.1
Saltstack ≫ Salt Version 2015.8.2
Saltstack ≫ Salt Version 2015.8.3
Opensuse ≫ Leap Version 42.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.52% 0.712
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://lists.opensuse.org/opensuse-updates/2016-03/msg00034.html
https://docs.saltstack.com/en/latest/topics/releases/2015.8.4.html
Vendor Advisory