The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight script before it runs they can ensure Salt-SSH runs their script with the privileges of the user running Salt-SSH. Do not make the copy path on the target predictable and ensure we check return codes of the scp command if the copy fails.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-admin/salt. | Dec 9, 2024 | Nov 14, 2024 |
| Suse | — | Upgrade salt-sshUpgrade salt-transactional-updateUpgrade saltUpgrade salt-cloudUpgrade salt-masterUpgrade salt-minionUpgrade python3-simplejsonUpgrade salt-zsh-completionUpgrade salt-docUpgrade salt-bash-completionUpgrade salt-proxyUpgrade salt-apiUpgrade salt-syndicUpgrade salt-fish-completionUpgrade salt-standalone-formulas-configurationUpgrade python3-salt | Nov 13, 2023 | Nov 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub