PT-2017-8352 · Saltstack+2 · Salt+2

Published

2016-04-07

·

Updated

2026-04-07

·

CVE-2016-3176

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Salt versions prior to 2015.5.10 Salt versions 2015.8.x prior to 2015.8.8
Description The issue allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient when PAM external authentication is enabled.
Recommendations For Salt versions prior to 2015.5.10, update to version 2015.5.10 or later. For Salt versions 2015.8.x prior to 2015.8.8, update to version 2015.8.8 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1939
CVE-2016-3176
GHSA-V2RP-9CPJ-PFW2
PYSEC-2017-33
SUSE-SU-2016:0970-1
SUSE-SU-2016:0972-1
SUSE-SU-2016:1343-1
USN-8153-1

Affected Products

Alt Linux
Salt
Ubuntu