QID 375416

Date Published: 2021-03-25

QID 375416: SaltStack Salt Master Multiple Security Vulnerabilities

SaltStack Salt is a software to automate the management and configuration of any infrastructure or application at scale.

The Salt Project has fixed multiple security issues in it's latest release

Affected Versions:
SaltStack Salt versions prior to 3002.6
SaltStack Salt versions prior to 3001.7
SaltStack Salt versions prior to 3000.9
Note: Previous versions are also affected.

QID Detection Logic:
This authenticated QID detects vulnerable salt-master versions by running the following command: salt-master --versions-report

This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised upgrade to the latest version of SaltStack 3002.6, SaltStack 3001.7, SaltStack 3000.9 to remediate these vulnerabilities.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SaltStack URL Logo github.com/saltstack/salt/releases