VDB
KO

PYSEC-2017-36

Details

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / salt
Introduced in: 0 Fixed in: 80d90307b07b3703428ecbb7c8bb468e28a9ae6d
Fix pip install --upgrade 'salt>=80d90307b07b3703428ecbb7c8bb468e28a9ae6d'

References