{"id":"CVE-2017-12791","aliases":["GHSA-xxvj-8g5m-4qgw","PYSEC-2017-35"],"url":"https://o3.security/vulnerability/CVE-2017-12791","summary":"SaltStack Salt Directory traversal vulnerability in minion id validation","details":"Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.","published":"2017-08-23T14:29:00.283Z","modified":"2026-07-09T16:56:24.190827719Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"salt","fixedVersion":"2016.11.7"},{"ecosystem":"PyPI","name":"salt","fixedVersion":"2017.7.1"}],"fix":{"url":"https://github.com/saltstack/salt/pull/42944","label":"saltstack/salt#42944"},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100384"},{"type":"FIX","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=872399"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1482006"},{"type":"FIX","url":"https://docs.saltstack.com/en/2016.11/topics/releases/2016.11.7.html"},{"type":"FIX","url":"https://docs.saltstack.com/en/latest/topics/releases/2017.7.1.html"},{"type":"FIX","url":"https://github.com/saltstack/salt/pull/42944"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T16:56:24.190827719Z"}}