VendorsSaltStacksalt2015.8.2
Vulnerabilities

SaltStack Salt 2015.8.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2016-1866
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
Published 2016-04-12 · Modified
8.1EPSS 0.015
CVE-2016-3176
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
Published 2017-01-31 · Modified
5.6EPSS 0.009