Improper Authentication in Salt - CVE-2020-11651

 

Improper Authentication in Salt - CVE-2020-11651

Published: May 4, 2020 / Updated: December 19, 2023


Vulnerability identifier: #VU27494
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11651
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the salt-master process "ClearFuncs" class does not properly validate method calls. A remote non-authenticated attacker can bypass authentication process and gain access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minion as root.

Note: this vulnerability is being actively exploited in the wild.


Affected software

Salt
Arch Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Transactional Server
Opensuse
Cisco Virtual Internet Routing Lab Personal Edition
Cisco Modeling Labs Corporate Edition
VMware vRealize Operations Manager (vROps)
salt (Debian package)
salt (Alpine package)
salt-minion (Ubuntu package)
salt-master (Ubuntu package)
salt-common (Ubuntu package)
python2-distro
python3-distro
salt-api (Ubuntu package)
salt-standalone-formulas-configuration
salt-ssh
salt-syndic
salt-fish-completion
salt-cloud
salt-doc
salt-bash-completion
salt-zsh-completion
salt-api
salt
python3-salt
salt-minion
salt-proxy
salt-transactional-update
salt-master
Dell EMC VxRail Appliance

How to mitigate CVE-2020-11651

Install updates from vendor's website.

Salt - addressed in versions 2019.2.4, 3000.2
salt (Debian package) - addressed in versions 2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1
salt (Alpine package) - addressed in versions 2019.2.4-r0, 3000.2-r0
salt-minion (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-master (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-common (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
python2-distro - update to 1.5.0-3.5.1
python3-distro - update to 1.5.0-3.5.1
Dell EMC VxRail Appliance - update to 7.0.203
salt-api (Ubuntu package) - addressed in versions 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-standalone-formulas-configuration - update to 3002.2-37.1
salt-ssh - update to 3002.2-37.1
salt-syndic - update to 3002.2-37.1
salt-fish-completion - update to 3002.2-37.1
salt-cloud - update to 3002.2-37.1
salt-doc - update to 3002.2-37.1
salt-bash-completion - update to 3002.2-37.1
salt-zsh-completion - update to 3002.2-37.1
salt-api - update to 3002.2-37.1
salt - update to 3002.2-37.1
python3-salt - update to 3002.2-37.1
salt-minion - update to 3002.2-37.1
salt-proxy - update to 3002.2-37.1
salt-transactional-update - update to 3002.2-37.1
salt-master - update to 3002.2-37.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins