Description
The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
5OSVsalt vulnerabilities↗2026-04-07 ▶ GHSASalt uses weak permissions on the cache data↗2022-05-17 ▶ OSVSalt uses weak permissions on the cache data↗2022-05-17 ▶ CVEListCVE-2015-8034: The state↗2017-01-30 ▶ OSVCVE-2015-8034: The state↗2017-01-30 ▶ 📋Vendor Advisories
2UbuntuSalt vulnerabilities↗2026-04-07 ▶ Red Hatsalt: Information leak from state.sls cache data stored as world-readable↗2015-10-30 ▶ 💬Community
3BugzillaCVE-2015-8034 salt: Information leak from state.sls cache data stored as world-readable [fedora-all]↗2015-12-07 ▶ BugzillaCVE-2015-8034 salt: Information leak from state.sls cache data stored as world-readable↗2015-12-07 ▶ BugzillaCVE-2015-8034 salt: Information leak from state.sls cache data stored as world-readable [epel-all]↗2015-12-07 ▶