Bug 950738 (CVE-2015-6941) - VUL-1: CVE-2015-6941: salt: win_useradd module and salt-cloud display passwords in debug log
Summary: VUL-1: CVE-2015-6941: salt: win_useradd module and salt-cloud display passwor...
Status: RESOLVED FIXED
Alias: CVE-2015-6941
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Minor
Target Milestone: ---
Assignee: Tim Serong
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:RedHat:CVE-2015-6941:5.5:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-16 11:00 UTC by Andreas Stieger
Modified: 2020-04-01 22:15 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-10-16 11:00:44 UTC
https://docs.saltstack.com/en/latest/topics/releases/2015.5.6.html
https://docs.saltstack.com/en/latest/topics/releases/2015.8.1.html

Security Fixes

CVE-2015-6941 - win_useradd module and salt-cloud display passwords in debug log

Updated the win_useradd module return data to no longer include the password of the newly created user. The password is now replaced with the string XXX-REDACTED-XXX. Updated the Salt Cloud debug output to no longer display win_password and sudo_password authentication credentials. Also updated the Linode driver to no longer display authentication credentials in debug logs. These credentials are now replaced with REDACTED in the debug output.
Comment 1 Andreas Stieger 2015-10-16 11:09:34 UTC
This probably resulted from upstream review of another security issue we track in our bug 943223.
Comment 2 Andreas Stieger 2015-10-16 11:18:24 UTC
Fix commit:
https://github.com/saltstack/salt/commit/aa71bae8aa7591a775b8c23cdc1615dd927588e2

Fixed upstream in tags:
v2014.7.7
v2015.5.6
v2015.8.1

Rest is discontinued upstream.

Affects openSUSE:13.2:Update/salt 2014.1.11
Affects openSUSE:13.1:Update/salt 0.16.4
Comment 4 Niels Abspoel 2015-12-08 18:55:13 UTC
Fixed with new upstream version release 2015.8.3

which are in systemsmanagement:saltstack
https://build.opensuse.org/request/show/347030

and leap update:
https://build.opensuse.org/request/show/347826