CVE-2015-1838

medium
Published 2017-04-13 · Modified 2023-11-08
CVSS v3
5.3
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v2
4.6
VIR risk
5.3

Description

modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

Predictions

Exploit likelihood
53%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/saltstack/salt/commit/e11298d7155e9982749483ca5538e46090caef9c

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://docs.saltstack.com/en/latest/topics/releases/2014.7.4.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=1212784

OS impact

OSVersionStatusFixed in
fedora fedora23affected

Package impact

EcosystemPackageVulnerableFixed
python PyPIsalt<2014.7.42014.7.4
python PyPIsalt<e11298d7155e9982749483ca5538e46090caef9c||<2014.7.4e11298d7155e9982749483ca5538e46090caef9c

Application impact

VendorProductVersionsFixed
saltstacksalt{"endIncluding":"2014.7.3"}

References

CWEs

CWE-19

Verify integrity in audit chain (admin only). AS-IS.