Loading vulnerability details…
CVSS v3.1
N/A
EPSS
3.05%
Published
Nov 5, 2013
Modified
Apr 28, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
Weaknesses (CWE)
Affected Products (11)
References (2)