668
VMScore

CVE-2017-14695

Published: 24/10/2017 Updated: 14/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in minion id validation in SaltStack Salt prior to 2016.3.8, 2016.11.x prior to 2016.11.8, and 2017.7.x prior to 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt 2016.11.0

saltstack salt 2016.11

saltstack salt

saltstack salt 2017.7.0

saltstack salt 2016.11.2

saltstack salt 2016.11.1

saltstack salt 2016.11.7

saltstack salt 2016.11.6

saltstack salt 2016.11.5

saltstack salt 2016.11.4

saltstack salt 2017.7.1

saltstack salt 2016.11.3

Vendor Advisories

Debian Bug report logs - #872399 salt: CVE-2017-12791: Directory traversal vulnerability on salt-master via crafted minion IDs Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 17 Aug 2017 03:54:02 UT ...
Debian Bug report logs - #879090 salt: CVE-2017-14696: Remote DoS via crated authentication request Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 19 Oct 2017 08:06:01 UTC Severity: important Tags ...
Debian Bug report logs - #879089 salt: CVE-2017-14695: Directory traversal in minion id validation Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 19 Oct 2017 08:03:01 UTC Severity: important Tags: ...
It has been discovered that maliciously crafted minion IDs can cause unwanted directory traversals on the salt-master The flaw is within the minion id validation which could allow certain minions to authenticate to a master despite not having the correct credentials To exploit the vulnerability, an attacker must create a salt-minion with an ID co ...