salt/doc/topics/releases/2017.7.2.rst
2020-02-26 00:57:58 +03:00

121 KiB

Salt 2017.7.2 Release Notes

Version 2017.7.2 is a bugfix release for 2017.7.0 <release-2017-7-0>.

Statistics

Security Fix

CVE-2017-14695 Directory traversal vulnerability in minion id validation in SaltStack. Allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. Credit for discovering the security flaw goes to: Julian Brost (julian@0x4a42.net)

CVE-2017-14696 Remote Denial of Service with a specially crafted authentication request. Credit for discovering the security flaw goes to: Julian Brost (julian@0x4a42.net)

Changelog for v2017.7.1..v2017.7.2

Generated at: 2018-05-26 21:06:12 UTC