vulnerability

FreeBSD: VID-50259D8B-243E-11EB-8BAE-B42E99975750 (CVE-2020-25592): salt -- multiple vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Nov 4, 2020
Added
Nov 13, 2020
Modified
Dec 16, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-50259D8B-243E-11EB-8BAE-B42E99975750:




SaltStack reports multiple security vulnerabilities in Salt 3002:




CVE-2020-16846: Prevent shell injections in netapi ssh client.


CVE-2020-17490: Prevent creating world readable private keys with the tls execution module.


CVE-2020-25592: Properly validate eauth credentials and tokens along with their ACLs.


Prior to this change eauth was not properly validated when calling Salt ssh via the salt-api.


Any value for 'eauth' or 'token' would allow a user to bypass authentication and make calls


to Salt ssh.





Solution(s)

freebsd-upgrade-package-py36-saltfreebsd-upgrade-package-py37-saltfreebsd-upgrade-package-py38-salt
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.