SaltStack Salt Directory traversal vulnerability in minion id validation
Critical severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Oct 21, 2024
Package
Affected versions
< 2016.11.7
>= 2017.7.0, < 2017.7.1
Patched versions
2016.11.7
2017.7.1
Description
Published by the National Vulnerability Database
Aug 23, 2017
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 22, 2024
Last updated
Oct 21, 2024
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
References