UBUNTU-CVE-2017-5192

Source
https://ubuntu.com/security/CVE-2017-5192
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-5192.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2017-5192
Related
Published
2017-09-26T14:29:00Z
Modified
2025-01-13T10:21:19Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

When using the localbatch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed. The LocalClient.cmdbatch() method client does not accept external_auth credentials and so access to it from salt-api has been removed for now. This vulnerability allows code execution for already-authenticated users and is only in effect when running salt-api as the root user.

References

Affected packages

Ubuntu:Pro:14.04:LTS / salt

Package

Name
salt
Purl
pkg:deb/ubuntu/salt@0.17.5+ds-1ubuntu0.1~esm4?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.16.0-1
0.16.4-2
0.17.1+dfsg-1
0.17.2-1
0.17.2-2
0.17.2-3
0.17.4-1
0.17.4-2
0.17.5-1
0.17.5+ds-1
0.17.5+ds-1ubuntu0.1~esm1
0.17.5+ds-1ubuntu0.1~esm2
0.17.5+ds-1ubuntu0.1~esm4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / salt

Package

Name
salt
Purl
pkg:deb/ubuntu/salt@2015.8.8+ds-1ubuntu0.1+esm2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2015.*

2015.5.3+ds-1
2015.8.1+ds-2
2015.8.3+ds-1
2015.8.3+ds-2
2015.8.3+ds-3
2015.8.5+ds-1
2015.8.7+ds-1
2015.8.8+ds-1
2015.8.8+ds-1ubuntu0.1~esm1
2015.8.8+ds-1ubuntu0.1
2015.8.8+ds-1ubuntu0.1+esm1
2015.8.8+ds-1ubuntu0.1+esm2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:18.04:LTS / salt

Package

Name
salt
Purl
pkg:deb/ubuntu/salt@2017.7.4+dfsg1-1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2017.7.4+dfsg1-1

Affected versions

2016.*

2016.11.5+ds-1
2016.11.8+dfsg1-1

2017.*

2017.7.2+dfsg1-2ubuntu1
2017.7.3+dfsg1-1

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "salt-api",
            "binary_version": "2017.7.4+dfsg1-1"
        },
        {
            "binary_name": "salt-cloud",
            "binary_version": "2017.7.4+dfsg1-1"
        },
        {
            "binary_name": "salt-common",
            "binary_version": "2017.7.4+dfsg1-1"
        },
        {
            "binary_name": "salt-doc",
            "binary_version": "2017.7.4+dfsg1-1"
        },
        {
            "binary_name": "salt-master",
            "binary_version": "2017.7.4+dfsg1-1"
        },
        {
            "binary_name": "salt-minion",
            "binary_version": "2017.7.4+dfsg1-1"
        },
        {
            "binary_name": "salt-proxy",
            "binary_version": "2017.7.4+dfsg1-1"
        },
        {
            "binary_name": "salt-ssh",
            "binary_version": "2017.7.4+dfsg1-1"
        },
        {
            "binary_name": "salt-syndic",
            "binary_version": "2017.7.4+dfsg1-1"
        }
    ]
}