QID 375416
Date Published: 2021-03-25
QID 375416: SaltStack Salt Master Multiple Security Vulnerabilities
SaltStack Salt is a software to automate the management and configuration of any infrastructure or application at scale.
The Salt Project has fixed multiple security issues in it's latest release
Affected Versions:
SaltStack Salt versions prior to 3002.6
SaltStack Salt versions prior to 3001.7
SaltStack Salt versions prior to 3000.9
Note: Previous versions are also affected.
QID Detection Logic:
This authenticated QID detects vulnerable salt-master versions by running the following command: salt-master --versions-report
This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Solution
Customers are advised upgrade to the latest version of SaltStack 3002.6, SaltStack 3001.7, SaltStack 3000.9 to remediate these vulnerabilities.
Vendor References
- SaltStack -
github.com/saltstack/salt/releases
CVEs related to QID 375416
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SaltStack |
|