CVE-2013-6617
SaltStack Salt 0.11.0-0.17.0 - Privilege Escalation via Improper Group Privilege Drop
Title source: llmDescription
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
References (1)
Core 1
Core References
Release Notes x_refsource_confirm
http://docs.saltstack.com/topics/releases/0.17.1.html
Scores
EPSS
0.0305
EPSS Percentile
86.2%
Details
CWE
CWE-264
Status
published
Products (12)
pypi/salt
0.11.0 - 0.17.1PyPI
saltstack/salt
0.11.0
saltstack/salt
0.12.0
saltstack/salt
0.13.0
saltstack/salt
0.14.0
saltstack/salt
0.15.0
saltstack/salt
0.15.1
saltstack/salt
0.16.0
saltstack/salt
0.16.2
saltstack/salt
0.16.3
... and 2 more
Published
Nov 05, 2013
Tracked Since
Feb 18, 2026