CVE-2017-14696Improper Input Validation in Salt

Severity
7.5HIGHNVD
EPSS
1.9%
top 16.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 24
Latest updateMay 17

Description

SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

PyPIsaltstack/salt2016.11.02016.11.8+5
NVDsaltstack/salt2016.3.7+11

Patches

🔴Vulnerability Details

4
GHSA
SaltStack Salt Denial of Service via a crafted authentication request2022-05-17
OSV
SaltStack Salt Denial of Service via a crafted authentication request2022-05-17
OSV
CVE-2017-14696: SaltStack Salt before 20162017-10-24
CVEList
CVE-2017-14696: SaltStack Salt before 20162017-10-24

📋Vendor Advisories

2
Ubuntu
Salt vulnerabilities2021-03-15
Red Hat
salt: Remote DoS via crafted authentication request2017-09-26

💬Community

2
Bugzilla
CVE-2017-14696 salt: Remote DoS via crafted authentication request2017-10-11
Bugzilla
CVE-2017-14695 CVE-2017-14696 salt: various flaws [epel-all]2017-10-11
CVE-2017-14696 — Improper Input Validation in Salt | cvebase