Critical Vulnerabilities Found in SaltStack – Patch Now

NJCCIC Advisory

Original Release Date: 11/5/2020

Summary

SaltStack disclosed three new vulnerabilities, two of which are considered critical, affecting Salt versions 3002 and prior. CVE-2020-16846 is a shell injection vulnerability and CVE-2020-25592 is an authentication bypass flaw. These two critical flaws affect any users running the Salt API. CVE-2020-17490, assessed to be low severity, affects any minions or masters that previously used the create_ca, create_csr, and create_self_signed_cert functions in the TLS module. Patches were released November 3, 2020.

Recommendations

The NJCCIC urges users and administrators to apply patches to SaltStack. Those using versions prior to 2015.8.10 need to update to a more current version prior to patching. Additional information can be found in the SaltStack blog post.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.