Improper Authentication in Salt - CVE-2020-25592

 

Improper Authentication in Salt - CVE-2020-25592

Published: November 6, 2020 / Updated: November 11, 2020


Vulnerability identifier: #VU48206
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25592
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing eauth credentials and tokens. A remote attacker can bypass authentication process and invoke Salt SSH.

Successful exploitation of the vulnerability will result in complete system compromise.


Affected software

Salt
Gentoo Linux
Arch Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Transactional Server
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
Opensuse
Ubuntu
Fedora
salt (Alpine package)
salt (Debian package)
salt-common (Ubuntu package)
python2-distro
python3-distro
salt
salt-master
python3-salt
salt-api
salt-cloud
salt-doc
salt-zsh-completion
salt-bash-completion
salt-fish-completion
salt-syndic
salt-standalone-formulas-configuration
salt-ssh
salt-proxy
salt-minion
salt-transactional-update
Dell EMC VxRail Appliance

How to mitigate CVE-2020-25592

Install updates from vendor's website.

Salt - addressed in versions 2019.2.6, 2019.2.7, 3000.4, 3000.5, 3001.2, 3001.3, 3002.1
salt (Alpine package) - update to 3002-r1
salt (Debian package) - update to 2018.3.4+dfsg1-6+deb10u2
salt-common (Ubuntu package) - update to Ubuntu Pro
python2-distro - update to 1.5.0-3.5.1
python3-distro - update to 1.5.0-3.5.1
Dell EMC VxRail Appliance - update to 7.0.203
salt - addressed in versions 3001.3-1.fc31, 3001.3-1.fc32, 3002.1-1.fc33
salt-master - update to 3002.2-37.1
python3-salt - update to 3002.2-37.1
salt - update to 3002.2-37.1
salt-api - update to 3002.2-37.1
salt-cloud - update to 3002.2-37.1
salt-doc - update to 3002.2-37.1
salt-zsh-completion - update to 3002.2-37.1
salt-bash-completion - update to 3002.2-37.1
salt-fish-completion - update to 3002.2-37.1
salt-syndic - update to 3002.2-37.1
salt-standalone-formulas-configuration - update to 3002.2-37.1
salt-ssh - update to 3002.2-37.1
salt-proxy - update to 3002.2-37.1
salt-minion - update to 3002.2-37.1
salt-transactional-update - update to 3002.2-37.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins