GHSA-j6gj-pg62-x8j6 · Severity: critical · Ecosystem: pip — SaltStack Salt Directory traversal vulnerability in minion id validation
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.
Conclusion & alert: CVE-2017-14695 is rated Moderate Risk (58.5/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.33%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-23 | 0.45% | 0.33% | -0.12% |
| 2 | 2025-05-10 | 0.47% | 0.45% | -0.02% |
| 3 | 2025-03-30 | — | 0.47% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.0 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-j6gj-pg62-x8j6 · Severity: critical · Ecosystem: pip — SaltStack Salt Directory traversal vulnerability in minion id validation
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2017-14695 |
suse
|
medium | CVE-2017-14695 severity moderate: SUSE including 447 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 695 product×package rows across 60 product lines (Container caasp/v4/salt-api, Container caasp/v4/salt-master, … (60 product lines)): Fixed 300, Known Affected 231, Known Not Affected 164. | https://www.suse.com/security/cve/CVE-2017-14695/ |
ubuntu
|
medium | CVE-2017-14695 medium priority: Ubuntu including 1 source packages (salt), 14 status rows across 14 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, trusty, upstream, xenial, zesty): not-affected 8, released 3, ignored 2, DNE 1. | https://ubuntu.com/security/CVE-2017-14695 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| saltstack | salt | <= 2016.3.7 | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11 | cpe:2.3:a:saltstack:salt:2016.11:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11.0 | cpe:2.3:a:saltstack:salt:2016.11.0:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11.1 | cpe:2.3:a:saltstack:salt:2016.11.1:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11.1 | cpe:2.3:a:saltstack:salt:2016.11.1:rc1:*:*:*:*:*:* |
| saltstack | salt | 2016.11.1 | cpe:2.3:a:saltstack:salt:2016.11.1:rc2:*:*:*:*:*:* |
| saltstack | salt | 2016.11.2 | cpe:2.3:a:saltstack:salt:2016.11.2:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11.3 | cpe:2.3:a:saltstack:salt:2016.11.3:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11.4 | cpe:2.3:a:saltstack:salt:2016.11.4:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11.5 | cpe:2.3:a:saltstack:salt:2016.11.5:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11.6 | cpe:2.3:a:saltstack:salt:2016.11.6:*:*:*:*:*:*:* |
| saltstack | salt | 2016.11.7 | cpe:2.3:a:saltstack:salt:2016.11.7:*:*:*:*:*:*:* |
| saltstack | salt | 2017.7.0 | cpe:2.3:a:saltstack:salt:2017.7.0:*:*:*:*:*:*:* |
| saltstack | salt | 2017.7.0 | cpe:2.3:a:saltstack:salt:2017.7.0:rc1:*:*:*:*:*:* |
| saltstack | salt | 2017.7.1 | cpe:2.3:a:saltstack:salt:2017.7.1:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html | Issue Tracking Release Notes Third Party Advisory |
| http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.html | Issue Tracking Release Notes Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1500748 | Issue Tracking Release Notes Third Party Advisory |
| https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.html | Issue Tracking Release Notes Vendor Advisory |
| https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.html | Issue Tracking Release Notes Vendor Advisory |
| https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.html | Issue Tracking Release Notes Vendor Advisory |
| https://github.com/saltstack/salt/commit/80d90307b07b3703428ecbb7c8bb468e28a9ae6d | Issue Tracking Patch Third Party Advisory |