Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
UBUNTU-CVE-2017-7893
See a problem?
Please try reporting it
to the source
first.
Source
https://ubuntu.com/security/CVE-2017-7893
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-7893.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-7893
Upstream
CVE-2017-7893
Published
2018-04-23T22:29:00Z
Modified
2025-07-18T16:43:58Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Ubuntu - medium
Summary
[none]
Details
In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.
References
https://ubuntu.com/security/CVE-2017-7893
https://docs.saltstack.com/en/2017.7/topics/releases/2016.3.6.html
https://github.com/saltstack/salt/issues/48939
https://patch-diff.githubusercontent.com/raw/saltstack/salt/pull/40159.patch
https://patch-diff.githubusercontent.com/raw/saltstack/salt/pull/40206.patch
https://github.com/saltstack/salt/issues/48939#issuecomment-410777638
https://www.cve.org/CVERecord?id=CVE-2017-7893
Affected packages
Ubuntu:Pro:14.04:LTS
/
salt
Package
Name
salt
Purl
pkg:deb/ubuntu/salt@0.17.5+ds-1ubuntu0.1~esm4?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
0.*
0.16.0-1
0.16.4-2
0.17.1+dfsg-1
0.17.2-1
0.17.2-2
0.17.2-3
0.17.4-1
0.17.4-2
0.17.5-1
0.17.5+ds-1
0.17.5+ds-1ubuntu0.1~esm1
0.17.5+ds-1ubuntu0.1~esm2
0.17.5+ds-1ubuntu0.1~esm4
Ubuntu:Pro:16.04:LTS
/
salt
Package
Name
salt
Purl
pkg:deb/ubuntu/salt@2015.8.8+ds-1ubuntu0.1+esm2?arch=source&distro=esm-apps/xenial
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
2015.*
2015.5.3+ds-1
2015.8.1+ds-2
2015.8.3+ds-1
2015.8.3+ds-2
2015.8.3+ds-3
2015.8.5+ds-1
2015.8.7+ds-1
2015.8.8+ds-1
2015.8.8+ds-1ubuntu0.1~esm1
2015.8.8+ds-1ubuntu0.1
2015.8.8+ds-1ubuntu0.1+esm1
2015.8.8+ds-1ubuntu0.1+esm2
UBUNTU-CVE-2017-7893 - OSV