CVE-2013-6617: SaltStack Salt
High severity, CVSS 10.0. EPSS: 3% chance of exploitation in the next 30 days.
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
Affected products
- SaltStack Salt: version 0.11.0 only; version 0.12.0 only; version 0.13.0 only; version 0.14.0 only; version 0.15.0 only; version 0.15.1 only; …
Published 2013-11-05. Last modified 2026-06-17.