Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
| Software | From | Fixed in |
|---|---|---|
| saltstack / salt | 2017.7.0 | 2017.7.0.x |
| saltstack / salt | - | 2016.11.6.x |