Executive brief
SaltStack Salt is a popular infrastructure automation and configuration management platform used by thousands of organizations to manage servers and network devices. A weakness in how the TLS module creates certificates allows local users with basic system access to read sensitive certificate files that should be protected, potentially exposing private encryption keys and compromising the security of the infrastructure.
Technical details
The TLS module in SaltStack Salt creates certificate files with overly permissive file permissions (CWE-732), allowing any local user with basic system access to read certificate private keys and other sensitive cryptographic material. This is a local privilege information-disclosure vulnerability requiring local system access and low-level user privileges. An attacker with local access can extract private keys from the exposed certificate files, enabling them to impersonate the Salt master or intercept encrypted communications. The issue affects all versions up to 3002; patches are available in versions 2015.8.13, 2016.3.8, 2016.11.10, 2017.7.8, 2018.3.5, 2019.2.6, 3000.4, and 3001.2.
Affected products
- SaltStack Salt 0.x through 3002, see advisory for specific version ranges
Timeline
- 2020-11-06: disclosed
- 2022-05-24: advisory