Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/11/25/2 | third party advisory mailing list |
http://www.securityfocus.com/bid/94553 | vdb entry third party advisory |
https://docs.saltstack.com/en/2015.8/ref/configuration/master.html#rotate-aes-key | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/11/25/3 | third party advisory mailing list |