MEDIUM 5.6 PyPI
Salt Insecure configuration of PAM external authentication service
GHSA-v2rp-9cpj-pfw2 · CVE-2016-3176 · PYSEC-2017-33
Published · Modified
Description
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2016-3176
- WEB https://docs.saltstack.com/en/latest/topics/releases/2015.5.10.html
- WEB https://docs.saltstack.com/en/latest/topics/releases/2015.8.8.html
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2017-33.yaml
- PACKAGE https://github.com/saltstack/salt
Ready to move
Start Securing
Free, no credit card | First findings in minutes