FixVibe

// código / holofote

SaltStack Salt Directory Traversal Advisory

A vulnerable Salt package can weaken Salt master authentication boundaries.

A pegada

Salt often sits in infrastructure automation rather than normal web request handling. That makes repo evidence important context, but not proof of exposure: a vulnerable package matters most when it is the deployed Salt master runtime and reachable from untrusted minions or networks.

Como funciona

The advisory affects the PyPI `salt` package before 2016.11.7 and the 2017.7.0 release line before 2017.7.1. The weakness is in minion ID validation, where crafted IDs can affect paths used by Salt master authentication logic.

O raio de impacto

When the affected Salt master runtime is deployed, crafted minion IDs can undermine expected credential checks and may lead to unauthorized access to the Salt master. The business impact depends on whether the repository actually deploys Salt master infrastructure, which network can reach it, and whether downstream packages include backported fixes.

// o que o fixvibe verifica

O que o FixVibe verifica

FixVibe repo scans look for high-confidence security patterns and dependency risk in source context. Reports identify the affected area and recommended fix. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

Defesas blindadas

Upgrade Salt to 2016.11.7, 2017.7.1, or a newer maintained release in the dependency source that controls deployment, then rebuild the Salt master/runtime image or host virtualenv. If Salt is supplied by the operating system, verify the host package includes the CVE fix or a vendor backport. Keep Salt master access limited to trusted management networks during rollout.

// rode no seu próprio app

Continue publicando enquanto o FixVibe vigia.

O FixVibe pressiona a superfície pública do seu app do jeito que um atacante faria — sem agente, sem instalação, sem cartão. Continuamos pesquisando novos padrões de vulnerabilidade e transformando isso em checks práticos e fixes prontos para Cursor, Claude e Copilot.

Código fonte
116
testes nessa categoria
módulos
76
checks dedicados de código fonte
todo scan
487+
testes em todas as categorias
  • Grátis — sem cartão, sem instalação, sem ping de Slack
  • Só colar uma URL — a gente crawla, sonda e reporta
  • Achados classificados por severidade, deduplicados no sinal
  • AI-ready prompts where code applies, plus operator steps for DNS/provider fixes
Rodar um scan grátis

// checks atuais · fixes práticos · publique com confiança

SaltStack Salt Directory Traversal Advisory — Holofote de Vulnerabilidade | FixVibe · FixVibe