Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
References
Link | Resource |
---|---|
https://docs.saltstack.com/en/latest/topics/releases/2014.7.6.html | Patch Release Notes Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1222960 | Issue Tracking Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2015/05/19/2 | Mailing List Patch Third Party Advisory |
https://groups.google.com/forum/#!topic/salt-users/8Kv1bytGD6c |
Configurations
Information
Published : 2017-08-25 11:29
Updated : 2018-08-13 14:47
NVD link : CVE-2015-4017
Mitre link : CVE-2015-4017
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
saltstack
- salt