{"id":"CVE-2017-5192","details":"When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.","aliases":["GHSA-f2h7-4f84-8qrm","PYSEC-2017-38"],"modified":"2026-07-08T15:11:29.087462Z","published":"2017-09-26T14:29:00.563Z","references":[{"type":"ADVISORY","url":"https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html"},{"type":"ADVISORY","url":"https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html"},{"type":"ADVISORY","url":"https://docs.saltstack.com/en/latest/topics/releases/2016.11.2.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/saltstack/salt","events":[{"introduced":"0"},{"last_affected":"399e9f57cc9611d385ddf86a0792b9f16dd95f75"},{"introduced":"11acecc43e2c2e4e9a0e73d76b46b035afe8d538"},{"last_affected":"ec59ae67c82e2bc63e16b05d95492a0756257207"}],"database_specific":{"cpe":["cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*","cpe:2.3:a:saltstack:salt:2016.3.0:*:*:*:*:*:*:*","cpe:2.3:a:saltstack:salt:2016.3.1:*:*:*:*:*:*:*","cpe:2.3:a:saltstack:salt:2016.3.2:*:*:*:*:*:*:*","cpe:2.3:a:saltstack:salt:2016.3.3:*:*:*:*:*:*:*","cpe:2.3:a:saltstack:salt:2016.3.4:*:*:*:*:*:*:*","cpe:2.3:a:saltstack:salt:2016.11.0:*:*:*:*:*:*:*","cpe:2.3:a:saltstack:salt:2016.11.1:*:*:*:*:*:*:*","cpe:2.3:a:saltstack:salt:2016.11.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2015.8.12"},{"introduced":"2016.3.0"},{"last_affected":"2016.3.0"},{"introduced":"2016.3.1"},{"last_affected":"2016.3.1"},{"introduced":"2016.3.2"},{"last_affected":"2016.3.2"},{"introduced":"2016.3.3"},{"last_affected":"2016.3.3"},{"introduced":"2016.3.4"},{"last_affected":"2016.3.4"},{"introduced":"2016.11.0"},{"last_affected":"2016.11.0"},{"introduced":"2016.11.1"},{"last_affected":"2016.11.1"},{"introduced":"2016.11.2"},{"last_affected":"2016.11.2"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2016.11.0","2016.11.1","2016.11.2","2016.3.0","2016.3.1","2016.3.2","2016.3.3","2016.3.4","v2016.9","v2016.11","v2016.3","v2016.11.2","v2016.11.1","v2015.8.12","v2016.11.0","v2016.11.0rc2","v2016.11.0rc1","v2015.8.11","v2015.8.9","v2015.8.8","v2015.8.4","v2015.8","v2015.8.3","v2015.8.2","v2015.8.1","v2015.8.0","v2015.8.0rc5","v2015.8.0rc4","v2015.8.0rc3","v2015.8.0rc2","v2015.8.0rc1","v2015.5","v2015.2","v2014.7","v2014.1","v0.17","v0.16","v0.15.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.5","v0.10.4","v0.10.3","v0.10.2","v0.10.1","v0.10.0","v0.9.9","v0.9.3","v0.9.2","v0.9.1","v0.9.0","v0.8.9","v0.8.7","v0.8.0","v0.7.0","v0.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5192.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}