release: | 2015-10-13 |
---|
Version 2015.5.6 is a bugfix release for 2015.5.0.
CVE-2015-6941 The Windows user
module and
salt-cloud
display passwords in log when log level is set to debug
or more verbose.
For the Windows user
module, the password is
now replaced with the string XXX-REDACTED-XXX
.
For salt-cloud, debug logging no longer displays win_password
and
sudo_password
authentication credentials.
CVE-2015-6918 Git state/execution modules log HTTPS auth credentials when
log level is set to debug
or more verbose.
These credentials are now replaced with REDACTED
in the debug output.
Thanks to Andreas Stieger <asteiger@suse.com> for bringing this to our
attention.
Generated at: 2018-05-27 22:13:00 UTC