Critical vulnerabilities in the SaltStack configuration management system

In the new releases of the centralized configuration management system SaltStack 3002.5, 3001.6, and 3000.8, a vulnerability (CVE-2020-28243) has been fixed that allowed an unprivileged local user of the host to escalate their privileges in the system. The issue was caused by a bug in the salt-minion handler used to receive commands from the central server. The vulnerability was identified in November but was only fixed now.

When performing the 'restartcheck' operation, it is possible to substitute arbitrary commands through manipulations with the process name. In particular, the request for package availability was made by launching the package manager with an argument based on the process name. The package manager is started by calling the popen function in shell mode, but without escaping special characters. By changing the process name and using characters like ';' and '|', it is possible to execute one's own code.

In addition to the noted issue in SaltStack 3002.5, nine other vulnerabilities have been fixed:

  • CVE-2021-25281 — due to insufficient privilege checks, a remote attacker can call any wheel module on the controlling master server via the SaltAPI, compromising the entire infrastructure.
  • CVE-2021-3197 — a problem in the SSH module to the minion allows arbitrary shell commands to be executed through argument substitution with the 'ProxyCommand' setting or by passing ssh_options via the API.
  • CVE-2021-25282 — unauthorized access to wheel_async allows arbitrary file rewriting beyond the base directory via requests to the SaltAPI, enabling the execution of arbitrary code in the system.
  • CVE-2021-25283 — a directory traversal bug in the wheel.pillar_roots.write handler in SaltAPI allows the addition of arbitrary templates to the jinja renderer.
  • CVE-2021-25284 — passwords set via webutils were logged in plain text in /var/log/salt/minion.
  • CVE-2021-3148 — the possibility of command substitution via SaltAPI calling salt.utils.thin.gen_thin().
  • CVE-2020-35662 — lack of verification SSL- of the certificate in the default configuration.
  • CVE-2021-3144 — the possibility of using authentication tokens for eauth after their expiration.
  • CVE-2020-28972 — SSL/TLS certificates were not checked in the code, server, allowing for MITM attacks.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster