An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Aug 22, 2024 | Mar 29, 2022 |
| Gentoo Linux | — | Upgrade app-admin/salt. | Nov 1, 2023 | Mar 29, 2022 |
| Suse | — | Upgrade salt-sshUpgrade salt-zsh-completionUpgrade salt-syndicUpgrade salt-proxyUpgrade salt-standalone-formulas-configurationUpgrade salt-docUpgrade salt-cloudUpgrade salt-transactional-updateUpgrade salt-masterUpgrade saltUpgrade salt-minionUpgrade python2-saltUpgrade salt-fish-completionUpgrade python3-saltUpgrade salt-apiUpgrade salt-bash-completion | Oct 26, 2022 | Mar 29, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub