QID 376110
QID 376110: SaltStack Salt Minion Command Injection Vulnerability
The Salt Project is an approach to infrastructure management built on a dynamic communication bus. Salt can be used for data-driven orchestration, remote execution for any infrastructure, configuration management for any app stack, and much more.
Affected Versions:
SaltStack Salt Minion versions 2016.9 through 3002.6
QID Detection Logic:
This authenticated QID detects vulnerable salt-minion versions by running the following command: salt-minion --version
a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion
Solution
Customers are advised upgrade to the latest version of SaltStack 3002.7
Vendor References
- SaltStack advisory -
github.com/saltstack/salt/releases
CVEs related to QID 376110
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-31607 |
|