Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Sep 20, 2017 | Aug 23, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Aug 23, 2017 |
| Debian | — | Upgrade salt | Jul 30, 2024 | Aug 23, 2017 |
| Freebsd | — | Upgrade py32-saltUpgrade py27-saltUpgrade py35-saltUpgrade py33-saltUpgrade py34-saltUpgrade py36-salt | Aug 23, 2017 | Aug 22, 2017 |
| Suse | — | Upgrade salt-sshUpgrade salt-apiUpgrade salt-standalone-formulas-configurationUpgrade salt-bash-completionUpgrade salt-syndicUpgrade salt-docUpgrade salt-proxyUpgrade salt-minionUpgrade salt-zsh-completionUpgrade saltUpgrade python2-saltUpgrade python3-saltUpgrade salt-masterUpgrade salt-fish-completionUpgrade salt-cloud | Sep 7, 2017 | Aug 16, 2017 |
| Ubuntu | — | Upgrade salt-proxy (Ubuntu Pro)Upgrade salt-common (Ubuntu Pro)Upgrade salt-master (Ubuntu Pro)Upgrade salt-ssh (Ubuntu Pro)Upgrade salt-syndic (Ubuntu Pro)Upgrade salt-minion (Ubuntu Pro)Upgrade salt-cloud (Ubuntu Pro)Upgrade salt-api (Ubuntu Pro) | Mar 22, 2023 | Aug 23, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 23, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub