CVE-2015-6941

CRITICAL

salt <2015.5.6-2015.8.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.

References (4)

Core 4
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://docs.saltstack.com/en/latest/topics/releases/2015.5.6.html
Release Notes, Vendor Advisory x_refsource_confirm
https://docs.saltstack.com/en/latest/topics/releases/2015.8.1.html
Issue Tracking, Patch, Third Party Advisory, VDB Entry x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1273066

Scores

CVSS v3 9.8
EPSS 0.0222
EPSS Percentile 80.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-534
Status published
Products (8)
pypi/salt 2015.5 - 2015.5.6PyPI
saltstack/salt_2015 5.0
saltstack/salt_2015 5.1
saltstack/salt_2015 5.2
saltstack/salt_2015 5.3
saltstack/salt_2015 5.4
saltstack/salt_2015 5.5
saltstack/salt_2015 8.0
Published Aug 09, 2017
Tracked Since Feb 18, 2026