Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4937
HistoryAug 22, 2017 - 8:22 a.m.

Directory Traversal

2017-08-2208:22:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.005

Percentile

77.3%

salt is vulnerable to directory traversal attacks. The attack is possible because minion ids are not properly checked, allowing a malicious user to pass a minion id containing escape characters to traverse the filesystem.