CVE-2017-14696
UnknownEPSS 2.74%
Last modified
CVE-2017-14696 is a vulnerability of currently unknown severity. SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.. EPSS estimates a 2.74% chance of exploitation in the next 30 days.
Description
SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Saltstack | Salt | <= 2016.3.7 |
| Saltstack | Salt | 2016.11 |
| Saltstack | Salt | 2016.11.0 |
| Saltstack | Salt | 2016.11.1 |
| Saltstack | Salt | 2016.11.2 |
| Saltstack | Salt | 2016.11.3 |
| Saltstack | Salt | 2016.11.4 |
| Saltstack | Salt | 2016.11.5 |
| Saltstack | Salt | 2016.11.6 |
| Saltstack | Salt | 2016.11.7 |
| Saltstack | Salt | 2017.7.0 |
| Saltstack | Salt | 2017.7.1 |
References
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.htmlIssue Tracking, Release Notes, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.htmlIssue Tracking, Release Notes, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500742Issue Tracking, Release Notes, Third Party Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://github.com/saltstack/salt/commit/5f8b5e1a0f23fe0f2be5b3c3e04199b57a53db5bIssue Tracking, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.htmlIssue Tracking, Release Notes, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.htmlIssue Tracking, Release Notes, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500742Issue Tracking, Release Notes, Third Party Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://github.com/saltstack/salt/commit/5f8b5e1a0f23fe0f2be5b3c3e04199b57a53db5bIssue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14696?
SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
How severe is CVE-2017-14696?
Severity scoring for CVE-2017-14696 is pending analysis. The EPSS model estimates a 2.74% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14696?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2017-14696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
