Executive brief
SaltStack Salt is a widely-used open-source infrastructure automation and configuration management platform. The salt-netapi component improperly validates authentication credentials and tokens, allowing an unauthenticated attacker to bypass authentication and execute arbitrary commands via Salt SSH. This could lead to complete compromise of managed systems and data exposure.
Technical details
This vulnerability is an authentication bypass (CWE-20: Improper Input Validation) in the salt-netapi REST API component. The flaw allows attackers to bypass eauth credential and token validation without proper authentication, gaining access to invoke Salt SSH commands. The attack vector is network-based and requires no authentication or user interaction. An attacker can leverage this to execute arbitrary commands on systems managed by the affected Salt installation. Patches are available in multiple release branches (2015.8.13, 2016.3.8, 2016.11.10, 2017.7.8, 2018.3.5, 2019.2.7, and later versions).
Affected products
- SaltStack Salt before 2015.8.13, 2016.3.0 before 2016.3.8, 2016.11.0 before 2016.11.10, 2017.7.0 before 2017.7.8, 2018.3.0 before 2018.3.5, 2019.2.0 before 2019.2.7, 3000.x before 3000.5, 3001.x before 3001.3, 3002.x before 3002.1
Timeline
- 2020-11-06: disclosed: Vulnerability publicly disclosed
- 2020-11: patched: Patches released across multiple release branches