The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file.
{
"binaries": [
{
"binary_version": "0.17.5+ds-1ubuntu0.1~esm4",
"binary_name": "salt-common"
},
{
"binary_version": "0.17.5+ds-1ubuntu0.1~esm4",
"binary_name": "salt-master"
},
{
"binary_version": "0.17.5+ds-1ubuntu0.1~esm4",
"binary_name": "salt-minion"
},
{
"binary_version": "0.17.5+ds-1ubuntu0.1~esm4",
"binary_name": "salt-ssh"
},
{
"binary_version": "0.17.5+ds-1ubuntu0.1~esm4",
"binary_name": "salt-syndic"
}
]
}