CVE-2017-12791: Path Traversal
A flaw in minion id validation was found which could allow certain minions to authenticate to a master despite not having the correct credentials. To exploit the vulnerability, an attacker must create a salt-minion with an ID containing characters that will cause a directory traversal.
External References:
https://docs.saltstack.com/en/2016.11/topics/releases/2016.11.7.html
Other sources
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12791?
CVE-2017-12791 has a severity rating that allows unauthorized minion authentication, posing a significant security risk.
How do I fix CVE-2017-12791?
To resolve CVE-2017-12791, upgrade Salt to version 2016.11.8 or later, or 2017.7.1 if using RedHat.
Which versions are affected by CVE-2017-12791?
CVE-2017-12791 affects SaltStack versions up to 2016.11.6 and 2017.7.0.
What type of exploitation is associated with CVE-2017-12791?
CVE-2017-12791 can be exploited by creating a malicious salt-minion that utilizes a specially crafted ID for directory traversal.
Is CVE-2017-12791 related to directory traversal vulnerabilities?
Yes, CVE-2017-12791 involves a directory traversal vulnerability which allows for unauthorized minion authentication.