PT-2017-8352 · Saltstack+2 · Salt+2

Publicado

2016-04-07

·

Atualizado

2026-04-07

·

CVE-2016-3176

CVSS v3.1

5.6

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Salt versions prior to 2015.5.10 Salt versions 2015.8.x prior to 2015.8.8
Description The issue allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient when PAM external authentication is enabled.
Recommendations For Salt versions prior to 2015.5.10, update to version 2015.5.10 or later. For Salt versions 2015.8.x prior to 2015.8.8, update to version 2015.8.8 or later.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1939
CVE-2016-3176
GHSA-V2RP-9CPJ-PFW2
PYSEC-2017-33
SUSE-SU-2016:0970-1
SUSE-SU-2016:0972-1
SUSE-SU-2016:1343-1
USN-8153-1

Produtos afetados

Alt Linux
Salt
Ubuntu