Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5323
HistoryOct 25, 2017 - 2:27 a.m.

Directory Traversal

2017-10-2502:27:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
37

EPSS

0.008

Percentile

81.1%

salt is vulnerable to directory traversal attacks. The attack is possible because of an incomplete fix for CVE-2017-12791. A malicious user can include escape characters and path separators into credentials when authenticating to a master to traverse the filesystem.