{"id":"CVE-2017-8109","aliases":["GHSA-xcx4-5wq7-g5g7","PYSEC-2017-82"],"url":"https://o3.security/vulnerability/CVE-2017-8109","summary":"SaltStack Salt Information Exposure","details":"The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).","published":"2017-04-25T17:59:00.180Z","modified":"2026-07-08T12:28:26.684574Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"salt","fixedVersion":"2016.11.4"}],"fix":{"url":"https://github.com/saltstack/salt/pull/40609","label":"saltstack/salt#40609"},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98095"},{"type":"FIX","url":"https://bugzilla.suse.com/show_bug.cgi?id=1035912"},{"type":"FIX","url":"https://docs.saltstack.com/en/latest/topics/releases/2016.11.4.html"},{"type":"FIX","url":"https://github.com/saltstack/salt/issues/40075"},{"type":"FIX","url":"https://github.com/saltstack/salt/pull/40609"},{"type":"FIX","url":"https://github.com/saltstack/salt/pull/40609/commits/6e34c2b5e5e849302af7ccd00509929c3809c658"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:28:26.684574Z"}}