CVE-2017-5192: SaltStack Salt
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.
Affected products
- SaltStack Salt: up to and including 2015.8.12; version 2016.3.0 only; version 2016.3.1 only; version 2016.3.2 only; version 2016.3.3 only; version 2016.3.4 only; …
Published 2017-09-26. Last modified 2026-06-17.