Original Release Date: 11/5/2020
SaltStack disclosed three new vulnerabilities, two of which are considered critical, affecting Salt versions 3002 and prior. CVE-2020-16846 is a shell injection vulnerability and CVE-2020-25592 is an authentication bypass flaw. These two critical flaws affect any users running the Salt API. CVE-2020-17490, assessed to be low severity, affects any minions or masters that previously used the create_ca, create_csr, and create_self_signed_cert functions in the TLS module. Patches were released November 3, 2020.
The NJCCIC urges users and administrators to apply patches to SaltStack. Those using versions prior to 2015.8.10 need to update to a more current version prior to patching. Additional information can be found in the SaltStack blog post.