CVE-2015-4017

Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
Configurations

Configuration 1 (hide)

cpe:2.3:a:saltstack:salt:2014.7.5:*:*:*:*:*:*:*

History

21 Nov 2024, 02:30

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2015/05/19/2 - Mailing List, Patch, Third Party Advisory () http://www.openwall.com/lists/oss-security/2015/05/19/2 - Mailing List, Patch, Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=1222960 - Issue Tracking, Patch, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1222960 - Issue Tracking, Patch, Third Party Advisory
References () https://docs.saltstack.com/en/latest/topics/releases/2014.7.6.html - Patch, Release Notes, Vendor Advisory () https://docs.saltstack.com/en/latest/topics/releases/2014.7.6.html - Patch, Release Notes, Vendor Advisory
References () https://groups.google.com/forum/#%21topic/salt-users/8Kv1bytGD6c - () https://groups.google.com/forum/#%21topic/salt-users/8Kv1bytGD6c -

07 Nov 2023, 02:25

Type Values Removed Values Added
References
  • {'url': 'https://groups.google.com/forum/#!topic/salt-users/8Kv1bytGD6c', 'name': 'https://groups.google.com/forum/#!topic/salt-users/8Kv1bytGD6c', 'tags': [], 'refsource': 'CONFIRM'}
  • () https://groups.google.com/forum/#%21topic/salt-users/8Kv1bytGD6c -

Information

Published : 2017-08-25 18:29

Updated : 2024-11-21 02:30


NVD link : CVE-2015-4017

Mitre link : CVE-2015-4017

CVE.ORG link : CVE-2015-4017


JSON object : View

Products Affected

saltstack

  • salt
CWE
CWE-295

Improper Certificate Validation