Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://docs.saltproject.io/en/3006/topics/releases/3006.12.html | release notes vendor advisory |
https://docs.saltproject.io/en/3007/topics/releases/3007.4.html | release notes vendor advisory |