An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-admin/salt. | Nov 1, 2023 | Jun 23, 2022 |
| Suse | — | Upgrade salt-proxyUpgrade salt-docUpgrade python3-saltUpgrade salt-fish-completionUpgrade salt-zsh-completionUpgrade salt-bash-completionUpgrade salt-syndicUpgrade salt-transactional-updateUpgrade salt-apiUpgrade salt-cloudUpgrade python2-saltUpgrade salt-sshUpgrade saltUpgrade salt-standalone-formulas-configurationUpgrade salt-minionUpgrade salt-master | Oct 26, 2022 | Jun 23, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub