CVE-2015-1839

medium
Published 2022-05-17 · Modified 2024-04-30
CVSS v3
5.3
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v2
4.6
VIR risk
5.3

Description

modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

Predictions

Exploit likelihood
53%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/saltstack/salt/commit/b49d0d4b5ca5c6f31f03e2caf97cef1088eeed81

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/saltstack/salt/commit/22d2f7a1ec93300c34e8c42d14ec39d51e610b5c

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://docs.saltstack.com/en/latest/topics/releases/2014.7.4.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=1212788

OS impact

OSVersionStatusFixed in
fedora fedora23affected

Package impact

EcosystemPackageVulnerableFixed
python PyPIsalt<2014.7.42014.7.4
python PyPIsalt<22d2f7a1ec93300c34e8c42d14ec39d51e610b5c||<2014.7.4b49d0d4b5ca5c6f31f03e2caf97cef1088eeed81

Application impact

VendorProductVersionsFixed
saltstacksalt{"endIncluding":"2014.7.3"}

References

CWEs

CWE-19

Verify integrity in audit chain (admin only). AS-IS.