CVE-2017-5200: SaltStack Salt

High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.

Affected products

  • SaltStack Salt: up to and including 2015.8.12; version 2016.3.0 only; version 2016.3.1 only; version 2016.3.2 only; version 2016.3.3 only; version 2016.3.4 only; …

Published 2017-09-26. Last modified 2026-06-17.