CVE-2017-14696: Input Validation
An input validation vulnerability with a specially crafted authentication request was discover in salt. A remote attacker can use this for a Denial of Service attack.
Other sources
SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14696?
CVE-2017-14696 has been classified as a moderate severity vulnerability due to its potential for causing a Denial of Service.
How do I fix CVE-2017-14696?
To fix CVE-2017-14696, upgrade SaltStack Salt to versions 2016.3.8, 2016.11.8, or 2017.7.2 or later.
What versions of SaltStack Salt are affected by CVE-2017-14696?
CVE-2017-14696 affects SaltStack Salt versions prior to 2016.3.8, 2016.11.8, and 2017.7.2.
Can CVE-2017-14696 be exploited remotely?
Yes, CVE-2017-14696 can be exploited remotely by delivering a specially crafted authentication request.
What type of attack can CVE-2017-14696 facilitate?
CVE-2017-14696 can facilitate a Denial of Service attack against the targeted SaltStack Salt instance.