CVE-2017-12791

saltstack/salt
on github

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
7.5 HIGH

Description

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:saltstack:salt:2017.7.0:*:*:*:*:*:*:*n/an/a2017.7.0
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*n/a2016.11.6 (including)*

External Links