CVE-2015-8034: SaltStack Salt
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file.
Affected products
- SaltStack Salt: up to and including 2015.8.2
Published 2017-01-30. Last modified 2026-06-17.