Candidate: CVE-2015-4017 PublicDate: 2017-08-25 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4017 http://www.openwall.com/lists/oss-security/2015/05/02/1 Description: Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules. Ubuntu-Description: Notes: sbeattie> vuln modules are only present in 2014.7.0 and later Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_salt: upstream: https://github.com/saltstack/salt/pull/23329/files upstream_salt: released (2014.7.6) precise_salt: DNE precise/esm_salt: DNE trusty_salt: not-affected (code not present) trusty/esm_salt: DNE (trusty was not-affected [code not present]) utopic_salt: not-affected vivid_salt: ignored (reached end-of-life) vivid/stable-phone-overlay_salt: DNE vivid/ubuntu-core_salt: DNE wily_salt: ignored (reached end-of-life) xenial_salt: not-affected (2015.8.8+ds-1) yakkety_salt: ignored (reached end-of-life) zesty_salt: ignored (reached end-of-life) artful_salt: ignored (reached end-of-life) bionic_salt: not-affected (2015.8.8+ds-1) devel_salt: not-affected (2015.8.8+ds-1)