VDB
KO

PYSEC-2013-26

Details

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / salt
Introduced in: 0.17.0 Fixed in: 0.17.1
Fix pip install --upgrade 'salt>=0.17.1'

References