CVE-2013-6617

SaltStack Salt 0.11.0-0.17.0 - Privilege Escalation via Improper Group Privilege Drop

Title source: llm
STIX 2.1

Description

The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.

References (1)

Core 1
Core References
Release Notes x_refsource_confirm
http://docs.saltstack.com/topics/releases/0.17.1.html

Scores

EPSS 0.0305
EPSS Percentile 86.2%

Details

CWE
CWE-264
Status published
Products (12)
pypi/salt 0.11.0 - 0.17.1PyPI
saltstack/salt 0.11.0
saltstack/salt 0.12.0
saltstack/salt 0.13.0
saltstack/salt 0.14.0
saltstack/salt 0.15.0
saltstack/salt 0.15.1
saltstack/salt 0.16.0
saltstack/salt 0.16.2
saltstack/salt 0.16.3
... and 2 more
Published Nov 05, 2013
Tracked Since Feb 18, 2026