Executive brief
The salt-master process ClearFuncs class in SaltStack Salt fails to properly validate method calls, leading to an authentication bypass. Remote unauthenticated attackers can exploit this to retrieve user tokens from the master or execute arbitrary commands on salt minions.
Affected products
- SaltStack Salt before 2019.2.4, 3000 before 3000.2
Timeline
- 2020-04-30: patched: Salt versions 2019.2.4 and 3000.2 released to address the vulnerability.
- 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: NVD publication date.