mirror of
https://github.com/valitydev/salt.git
synced 2024-11-07 08:58:59 +00:00
16 lines
712 B
ReStructuredText
16 lines
712 B
ReStructuredText
===========================
|
|
Salt 2016.3.7 Release Notes
|
|
===========================
|
|
|
|
Version 2016.3.7 is a bugfix release for :ref:`2016.3.0 <release-2016-3-0>`.
|
|
|
|
Changes for v2016.3.6..v2016.3.7
|
|
--------------------------------
|
|
|
|
Security Fix
|
|
============
|
|
|
|
CVE-2017-12791 Maliciously crafted minion IDs can cause unwanted directory traversals on the Salt-master
|
|
|
|
Correct a flaw in minion id validation which could allow certain minions to authenticate to a master despite not having the correct credentials. To exploit the vulnerability, an attacker must create a salt-minion with an ID containing characters that will cause a directory traversal. Credit for discovering the security flaw goes to: Vernhk@qq.com
|