Salt: Multiple vulnerabilities — GLSA 202103-01

Multiple vulnerabilities have been found in Salt, the worst of which could allow remote attacker to execute arbitrary commands.

Affected packages

app-admin/salt on all architectures
Affected versions < 3000.8
Unaffected versions >= 3000.8

Background

Salt is a fast, intelligent and scalable automation engine.

Description

Multiple vulnerabilities have been discovered in Salt. Please review the CVE identifiers referenced below for details.

Impact

A remote attacker could possibly execute arbitrary commands via salt-api, cause a Denial of Service condition, bypass access restrictions or disclose sensitive information.

Workaround

There is no known workaround at this time.

Resolution

All Salt users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-admin/salt-3000.8"
 

References

Release date
March 31, 2021

Latest revision
March 31, 2021: 1

Severity
normal

Exploitable
local, remote

Bugzilla entries