CVE-2017-12791: Path Traversal

Published Aug 16, 2017
·
Updated

A flaw in minion id validation was found which could allow certain minions to authenticate to a master despite not having the correct credentials. To exploit the vulnerability, an attacker must create a salt-minion with an ID containing characters that will cause a directory traversal.

External References:

https://docs.saltstack.com/en/2016.11/topics/releases/2016.11.7.html

Other sources

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

Launchpad

Affected Software

9 affected componentsFixes available
debian/salt<=2016.11.5+ds-1, <=2014.1.13+ds-1
2016.11.8+dfsg1-12016.11.2+ds-1+deb9u1
redhat/salt<2016.3.7
2016.3.7
redhat/salt<2016.11.7
2016.11.7
redhat/salt<2017.7.1
2017.7.1
debian/salt
pip/salt>=2017.7.0<2017.7.1
2017.7.1
pip/salt<2016.11.7
2016.11.7
SaltStack Salt<=2016.11.6
SaltStack Salt=2017.7.0

Event History

Aug 23, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·01:22 AM
Jan 11, 2024
Data Sourced
via Launchpad·10:27 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·11:59 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2017-12791?

CVE-2017-12791 has a severity rating that allows unauthorized minion authentication, posing a significant security risk.

2

How do I fix CVE-2017-12791?

To resolve CVE-2017-12791, upgrade Salt to version 2016.11.8 or later, or 2017.7.1 if using RedHat.

3

Which versions are affected by CVE-2017-12791?

CVE-2017-12791 affects SaltStack versions up to 2016.11.6 and 2017.7.0.

4

What type of exploitation is associated with CVE-2017-12791?

CVE-2017-12791 can be exploited by creating a malicious salt-minion that utilizes a specially crafted ID for directory traversal.

5

Is CVE-2017-12791 related to directory traversal vulnerabilities?

Yes, CVE-2017-12791 involves a directory traversal vulnerability which allows for unauthorized minion authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203