← Back

CVE-2016-1866

nvd nist
Published: Apr 12, 2016Modified: May 6, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

Affected (5)

Products: Saltstack: Salt · Opensuse: Leap
1 product
Salt
1 product
Leap
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Saltstack
Version 2015.8.0
Version 2015.8.1
Version 2015.8.2
Version 2015.8.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.1

References (4)

Timeline

No history available yet.