{"id":"GHSA-cxm4-7qcw-267r","summary":"salt password information leaked in debug logs","details":"win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.","aliases":["CVE-2015-6941","PYSEC-2017-71"],"modified":"2024-10-21T22:00:57.065742Z","published":"2022-05-17T01:59:05Z","database_specific":{"cwe_ids":["CWE-200"],"github_reviewed_at":"2024-05-01T11:21:22Z","github_reviewed":true,"nvd_published_at":"2017-08-09T16:29:00Z","severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-6941"},{"type":"WEB","url":"https://github.com/saltstack/salt/commit/c0689e32154c41f59840ae10ffc5fbfa30618710"},{"type":"WEB","url":"https://github.com/saltstack/salt/commit/fdd35374562658f4a20767a3703fab93d92f9ca9"},{"type":"WEB","url":"https://github.com/twangboy/salt/commit/c0689e32154c41f59840ae10ffc5fbfa30618710"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1273066"},{"type":"WEB","url":"https://docs.saltstack.com/en/latest/topics/releases/2015.5.6.html"},{"type":"WEB","url":"https://docs.saltstack.com/en/latest/topics/releases/2015.8.1.html"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2017-71.yaml"},{"type":"PACKAGE","url":"https://github.com/saltstack/salt"}],"affected":[{"package":{"name":"salt","ecosystem":"PyPI","purl":"pkg:pypi/salt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2015.5"},{"fixed":"2015.5.6"}]}],"versions":["2015.5.0","2015.5.1","2015.5.2","2015.5.3","2015.5.4","2015.5.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cxm4-7qcw-267r/GHSA-cxm4-7qcw-267r.json"}},{"package":{"name":"salt","ecosystem":"PyPI","purl":"pkg:pypi/salt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2015.8"},{"fixed":"2015.8.1"}]}],"versions":["2015.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cxm4-7qcw-267r/GHSA-cxm4-7qcw-267r.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}