VYPR
Critical severity9.8NVD Advisory· Published Aug 23, 2017· Updated May 13, 2026

CVE-2017-12791

CVE-2017-12791

Description

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
saltPyPI
< 2016.11.72016.11.7
saltPyPI
>= 2017.7.0, < 2017.7.12017.7.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.