ALT-PU-2017-1436-1
Closed vulnerabilities
Modified: 2025-04-20
CVE-2017-12791
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
- http://www.securityfocus.com/bid/100384
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=872399
- https://bugzilla.redhat.com/show_bug.cgi?id=1482006
- https://docs.saltstack.com/en/2016.11/topics/releases/2016.11.7.html
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.1.html
- https://github.com/saltstack/salt/pull/42944
- http://www.securityfocus.com/bid/100384
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=872399
- https://bugzilla.redhat.com/show_bug.cgi?id=1482006
- https://docs.saltstack.com/en/2016.11/topics/releases/2016.11.7.html
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.1.html
- https://github.com/saltstack/salt/pull/42944
Modified: 2025-04-20
CVE-2017-14695
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1500748
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.html
- https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.html
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.html
- https://github.com/saltstack/salt/commit/80d90307b07b3703428ecbb7c8bb468e28a9ae6d
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1500748
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.html
- https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.html
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.html
- https://github.com/saltstack/salt/commit/80d90307b07b3703428ecbb7c8bb468e28a9ae6d
Modified: 2025-04-20
CVE-2017-14696
SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1500742
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.html
- https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.html
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.html
- https://github.com/saltstack/salt/commit/5f8b5e1a0f23fe0f2be5b3c3e04199b57a53db5b
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1500742
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.html
- https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.html
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.html
- https://github.com/saltstack/salt/commit/5f8b5e1a0f23fe0f2be5b3c3e04199b57a53db5b
Modified: 2025-04-20
CVE-2017-8109
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).
- http://www.securityfocus.com/bid/98095
- https://bugzilla.suse.com/show_bug.cgi?id=1035912
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.4.html
- https://github.com/saltstack/salt/issues/40075
- https://github.com/saltstack/salt/pull/40609
- https://github.com/saltstack/salt/pull/40609/commits/6e34c2b5e5e849302af7ccd00509929c3809c658
- http://www.securityfocus.com/bid/98095
- https://bugzilla.suse.com/show_bug.cgi?id=1035912
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.4.html
- https://github.com/saltstack/salt/issues/40075
- https://github.com/saltstack/salt/pull/40609
- https://github.com/saltstack/salt/pull/40609/commits/6e34c2b5e5e849302af7ccd00509929c3809c658