Back

MEDIUM

salt: insecure configuration of PAM external authentication service

Published Jan 31, 2017

Description

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 31, 2017
Updated Aug 5, 2024
Reserved Mar 15, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 23, 2016
GHSA-V2RP-9CPJ-PFW2