UBUNTU-CVE-2017-12791
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-12791
UBUNTU-CVE-2017-12791
Summary:
Details: Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
References: https://ubuntu.com/security/CVE-2017-12791, https://github.com/saltstack/salt/pull/42944, https://github.com/saltstack/salt/commit/6366e05d0d70bd709cc4233c3faf32a759d0173a, https://docs.saltstack.com/en/2016.11/topics/releases/2016.11.7.html, https://www.cve.org/CVERecord?id=CVE-2017-12791, https://ubuntu.com/security/notices/USN-4769-1
Affected packages
Package
Name: salt
Purl: pkg:deb/ubuntu/[email protected]+ds-1ubuntu0.1~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
