CVE-2017-5192

Description

When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.149

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in VMware SALT 2016.11.0Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.11.1Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.11.2Windows
Multiple Vulnerabilities are affected in VMware SALT 2015.8.12Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.0Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.1Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.2Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.3.3Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.4Windows
Multiple vulnerabilities are fixed in Python-salt 2015.8.13Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt 2016.11.2Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt 2016.3.5Windows
Multiple vulnerabilities are fixed in Python-salt for linux 2015.8.13Linux
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt for linux 2016.11.2Linux
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt for linux 2016.3.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234