salt/doc/topics/releases/2017.7.1.rst
2020-02-26 00:57:58 +03:00

11 KiB

Salt 2017.7.1 Release Notes

Version 2017.7.1 is a bugfix release for 2017.7.0 <release-2017-7-0>.

Statistics

Security Fix

CVE-2017-12791 Maliciously crafted minion IDs can cause unwanted directory traversals on the Salt-master

Correct a flaw in minion id validation which could allow certain minions to authenticate to a master despite not having the correct credentials. To exploit the vulnerability, an attacker must create a salt-minion with an ID containing characters that will cause a directory traversal. Credit for discovering the security flaw goes to: Vernhk@qq.com

Changelog for v2017.7.0..v2017.7.1

Generated at: 2018-05-26 20:28:44 UTC