1
0

2016.11.10.rst 659 B

1234567891011121314151617
  1. =============================
  2. Salt 2016.11.10 Release Notes
  3. =============================
  4. Version 2016.11.10 is a security release for :ref:`2016.11.0 <release-2016-11-0>`.
  5. Changes for v2016.11.9..v2016.11.10
  6. -----------------------------------
  7. Security Fix
  8. ============
  9. CVE-2018-15751 Remote command execution and incorrect access control when using salt-api.
  10. CVE-2018-15750 Directory traversal vulnerability when using salt-api. Allows an attacker to determine what files exist on a server when querying /run or /events.
  11. Credit and thanks for discovery and responsible disclosure: nullbr4in, xcuter, koredge, loupos, blackcon, Naver Business Platform