Vulnerability identifier: #VU58292
Vulnerability risk: Low
CVSSv3.1:
CVE-ID:
CWE-ID:
Exploitation vector: Local
Exploit availability:
Vulnerable software:
Salt
Web applications /
Remote management & hosting panels
Vendor: SaltStack
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to command injection in the snapper module. A local user can escalate privileges on a minion.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Salt: 3002 - 3002.6, 3001 - 3001.7, 3000 - 3000.9, 2019.2 - 2019.8, 2018.2 - 2018.11, 2017.5 - 2017.7.8, 2016.9 - 2016.11.10
Fixed software versions
CPE
External links
http://sec.stealthcopter.com/saltstack-snapper-minion-privledge-escaltion/
http://bugzilla.redhat.com/show_bug.cgi?id=1953065
http://github.com/saltstack/salt/commit/43e4ac985a2fc5f0d596c9fc6bc700b0d1af5344
http://saltproject.io/security_announcements/salt-security-advisory-2021-sep-02/
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?