Candidate: CVE-2015-8034 PublicDate: 2017-01-30 22:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8034 https://github.com/cachedout/salt/commit/097838ec0c52b1e96f7f761e5fb3cd7e79808741 https://github.com/saltstack/salt/issues/28455 Description: The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=807356 Priority: high Discovered-by: Zach Malone Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N [3.3 LOW] Patches_salt: upstream: https://github.com/cachedout/salt/commit/097838ec0c52b1e96f7f761e5fb3cd7e79808741 upstream_salt: released (2015.8.3+ds-1) precise_salt: DNE precise/esm_salt: DNE trusty_salt: ignored (reached end-of-life) trusty/esm_salt: DNE (trusty was needed) vivid_salt: ignored (reached end-of-life) vivid/stable-phone-overlay_salt: DNE vivid/ubuntu-core_salt: DNE wily_salt: ignored (reached end-of-life) xenial_salt: not-affected (2015.8.8+ds-1) yakkety_salt: not-affected (2016.3.1+ds-1) zesty_salt: not-affected artful_salt: not-affected bionic_salt: not-affected cosmic_salt: not-affected disco_salt: not-affected devel_salt: not-affected