Saltstack Version 2019.2.0+ds-1 Critical-Vulnerability ?

Status
Not open for further replies.

Meik

Platinum Partner
Joined
Aug 8, 2017
Messages
2
Reaction score
0
Hello, 3CX Team,

we have just received information about a critical security vulnerability in Saltstack from a customer's monitoring.

This has probably been fixed since the update of 2020-04-29.
https://repo.saltstack.com/apt/debian/9/amd64/2019.2/
but not in the repository configured in the PBX:
https://repo.saltstack.com/apt/debian/9/amd64/archive/2019.2.0/

According to the description it probably relates specifically to the master installation, but according to F-Secure it is also correspondingly dangerous for the client (Minion)
https://help.saltstack.com/hc/en-us...-New-SaltStack-Release-Critical-Vulnerability
https://labs.f-secure.com/advisories/saltstack-authorization-bypass
https://www.heise.de/security/meldu...Konfigurationssoftware-Saltstack-4714545.html

Saltstack is also set up on installations where Instance Manager is not active...
What is Saltstack used for here?
How much external access is possible from the Master to the Minion?
How can it be deactivated, what are the functional limitations?

Be grateful for very fast information!

Thank you - Meik
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,948
Messages
589,880
Members
164,841
Latest member
erre