CVE-2017-14695: Path Traversal
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.
Other sources
Directory traversal vulnerability in minion id validation in SaltStack. Allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
References:
https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14695?
CVE-2017-14695 is classified as a medium-severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2017-14695?
To remediate CVE-2017-14695, upgrade to Salt version 2016.3.8, 2016.11.8, or 2017.7.2 or later.
Who is affected by CVE-2017-14695?
CVE-2017-14695 affects SaltStack Salt versions prior to 2016.3.8, 2016.11.8, and 2017.7.2.
What does CVE-2017-14695 involve?
CVE-2017-14695 is a directory traversal vulnerability that allows remote minions to authenticate with crafted minion IDs.
Can CVE-2017-14695 be exploited remotely?
Yes, CVE-2017-14695 can be exploited remotely by unauthorized minions submitting manipulated IDs.