QID 376110

QID 376110: SaltStack Salt Minion Command Injection Vulnerability

The Salt Project is an approach to infrastructure management built on a dynamic communication bus. Salt can be used for data-driven orchestration, remote execution for any infrastructure, configuration management for any app stack, and much more.

Affected Versions:
SaltStack Salt Minion versions 2016.9 through 3002.6

QID Detection Logic:
This authenticated QID detects vulnerable salt-minion versions by running the following command: salt-minion --version

a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised upgrade to the latest version of SaltStack 3002.7
    Vendor References

    CVEs related to QID 376110

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-31607 URL Logo saltproject.io/security_announcements/salt-security-advisory-2021-sep-02/