CVE-2017-8109: SaltStack Salt

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

Affected products

  • SaltStack Salt: version 2016.11 only; version 2016.11.0 only; version 2016.11.1 only; version 2016.11.2 only; version 2016.11.3 only

Published 2017-04-25. Last modified 2026-06-17.