USN-6849-1: Salt vulnerabilities
25 June 2024
Several security issues were fixed in Salt.
Releases
Packages
- salt - Infrastructure management built on a dynamic communication bus
Details
It was discovered that Salt incorrectly validated method calls and
sanitized paths. A remote attacker could possibly use this issue to access
some methods without authentication. (CVE-2020-11651, CVE-2020-11652)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.04
-
salt-common
-
0.17.5+ds-1ubuntu0.1~esm2
Available with Ubuntu Pro
-
salt-master
-
0.17.5+ds-1ubuntu0.1~esm2
Available with Ubuntu Pro
-
salt-minion
-
0.17.5+ds-1ubuntu0.1~esm2
Available with Ubuntu Pro
After a standard system update you need to restart Salt to make all the
necessary changes.
References
Related notices
- USN-4459-1: salt-cloud, salt-ssh, salt-api, salt-syndic, salt-minion, salt-common, salt-proxy, salt-master, salt-doc, salt