7.5
CVSSv2

CVE-2017-12791

Published: 23/08/2017 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in minion id validation in SaltStack Salt prior to 2016.11.7 and 2017.7.x prior to 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt 2017.7.0

saltstack salt

Vendor Advisories

Debian Bug report logs - #872399 salt: CVE-2017-12791: Directory traversal vulnerability on salt-master via crafted minion IDs Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 17 Aug 2017 03:54:02 UT ...
Debian Bug report logs - #879090 salt: CVE-2017-14696: Remote DoS via crated authentication request Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 19 Oct 2017 08:06:01 UTC Severity: important Tags ...
Debian Bug report logs - #879089 salt: CVE-2017-14695: Directory traversal in minion id validation Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 19 Oct 2017 08:03:01 UTC Severity: important Tags: ...
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016117 and 20177x before 201771 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID ...
It has been discovered that maliciously crafted minion IDs can cause unwanted directory traversals on the salt-master The flaw is within the minion id validation which could allow certain minions to authenticate to a master despite not having the correct credentials To exploit the vulnerability, an attacker must create a salt-minion with an ID co ...