VDB
Sign up
—

PYSEC-2017-36

Quick fix

PYSEC-2017-36 — salt: upgrade to the fixed version with the command below.

pip install --upgrade 'salt>=80d90307b07b3703428ecbb7c8bb468e28a9ae6d'

Details

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/salt
Introduced in: 0Fixed in: 80d90307b07b3703428ecbb7c8bb468e28a9ae6d
Fixpip install --upgrade 'salt>=80d90307b07b3703428ecbb7c8bb468e28a9ae6d'

References