Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14695

Опубликовано: 26 сент. 2017
Источник: redhat
CVSS3: 8

Описание

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3saltWill not fix
Red Hat Ceph Storage 2saltWill not fix
Red Hat Storage Console 2saltWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1500748salt: Directory traversal in minion id validation

8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.

CVSS3: 9.8
nvd
больше 8 лет назад

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.

CVSS3: 9.8
debian
больше 8 лет назад

Directory traversal vulnerability in minion id validation in SaltStack ...

CVSS3: 9.8
github
больше 3 лет назад

SaltStack Salt Directory traversal vulnerability in minion id validation

suse-cvrf
больше 8 лет назад

Security update for salt

8 High

CVSS3