CVE-2017-12791 PUBLISHED

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

EPSS 0.93% · 76.0th percentile

Risk Scores

EPSS Score
0.93%
76.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSsalt0, 0.16.0-1, 0.16.4-2
Ubuntu:Pro:16.04:LTSsalt0, 2015.5.3+ds-1, 2015.8.1+ds-2

Timeline

References

Open in Interactive Console →