QID 375417

Date Published: 2021-03-25

QID 375417: SaltStack Salt Minion Multiple Security Vulnerabilities

SaltStack Salt is a software to automate the management and configuration of any infrastructure or application at scale.

The Salt Project has issued a secondary fix for a command injection vulnerability after the first attempt to patch the issue partially failed.

Affected Versions:
SaltStack Salt Minion versions prior to 3002.6
SaltStack Salt Minion versions prior to 3001.7
SaltStack Salt Minion versions prior to 3000.9
Note: Previous versions are also affected.

QID Detection Logic:
This authenticated QID detects vulnerable salt-minion versions by running the following command: salt-minion --versions-report

This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised upgrade to the latest version of SaltStack 3002.6, SaltStack 3001.7, SaltStack 3000.9 to remediate these vulnerabilities.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SaltStack URL Logo github.com/saltstack/salt/releases