9.8

CVE-2020-11651

Warnung
Exploit
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Saltstack ≫ Salt Version < 2019.2.4
Saltstack ≫ Salt Version >= 3000 < 3000.2
Opensuse ≫ Leap Version 15.1
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

SaltStack Salt Authentication Bypass Vulnerability

Schwachstelle

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 96.61% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4459-1/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4676
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html
Third Party Advisory
Mailing List
http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
http://www.vmware.com/security/advisories/VMSA-2020-0009.html
Third Party Advisory
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
Vendor Advisory
https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/05/msg00027.html
Third Party Advisory
Mailing List
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11651
US Government Resource