CVE-2017-5192
Description
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.
Risk Information
Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.149
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in VMware SALT 2016.11.0 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.11.1 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.11.2 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2015.8.12 | Windows |
| Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.0 | Windows |
| Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.1 | Windows |
| Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.2 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.3.3 | Windows |
| Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.4 | Windows |
| Multiple vulnerabilities are fixed in Python-salt 2015.8.13 | Windows |
| Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt 2016.11.2 | Windows |
| Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt 2016.3.5 | Windows |
| Multiple vulnerabilities are fixed in Python-salt for linux 2015.8.13 | Linux |
| Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt for linux 2016.11.2 | Linux |
| Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt for linux 2016.3.5 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234