CVE-2015-6941: SaltStack Salt 2015

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.

Affected products

  • SaltStack Salt 2015: version 5.0 only; version 5.1 only; version 5.2 only; version 5.3 only; version 5.4 only; version 5.5 only; …

Published 2017-08-09. Last modified 2026-06-17.