QID 375417
Date Published: 2021-03-25
QID 375417: SaltStack Salt Minion Multiple Security Vulnerabilities
SaltStack Salt is a software to automate the management and configuration of any infrastructure or application at scale.
The Salt Project has issued a secondary fix for a command injection vulnerability after the first attempt to patch the issue partially failed.
Affected Versions:
SaltStack Salt Minion versions prior to 3002.6
SaltStack Salt Minion versions prior to 3001.7
SaltStack Salt Minion versions prior to 3000.9
Note: Previous versions are also affected.
QID Detection Logic:
This authenticated QID detects vulnerable salt-minion versions by running the following command: salt-minion --versions-report
This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Solution
Customers are advised upgrade to the latest version of SaltStack 3002.6, SaltStack 3001.7, SaltStack 3000.9 to remediate these vulnerabilities.
Vendor References
- SaltStack -
github.com/saltstack/salt/releases
CVEs related to QID 375417
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SaltStack |
|