Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12791

Опубликовано: 23 авг. 2017
Источник: debian

Описание

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
saltfixed2016.11.8+dfsg1-1package
saltfixed2016.11.2+ds-1+deb9u1stretchpackage
saltno-dsajessiepackage

Примечания

  • https://github.com/saltstack/salt/pull/42944

  • https://github.com/saltstack/salt/commit/6366e05d0d70bd709cc4233c3faf32a759d0173a

  • https://docs.saltstack.com/en/2016.11/topics/releases/2016.11.7.html

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

CVSS3: 5.3
redhat
почти 8 лет назад

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

CVSS3: 9.8
nvd
почти 8 лет назад

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

suse-cvrf
почти 8 лет назад

Security update for salt

suse-cvrf
больше 7 лет назад

Security update for Salt