CVE-2014-3563

SaltStack Salt < 2014.1.10 - Local Privilege Escalation via Temporary File Handling

Title source: llm
STIX 2.1

Description

Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95392
Patch mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2014/q3/428
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69319
Patch, Vendor Advisory x_refsource_confirm
http://docs.saltstack.com/en/latest/topics/releases/2014.1.10.html

Scores

EPSS 0.0041
EPSS Percentile 32.3%

Details

CWE
CWE-59
Status published
Products (2)
pypi/salt 0 - 2014.1.10PyPI
saltstack/salt < 2014.1.9
Published Aug 22, 2014
Tracked Since Feb 18, 2026