Critical vulnerabilities in the SaltStack configuration management system
In the new releases of the centralized configuration management system SaltStack 3002.5, 3001.6, and 3000.8, a vulnerability (CVE-2020-28243) has been fixed that allows a non-privileged local user on the host to escalate their privileges in the system. The issue was caused by a bug in the salt-minion handler, which is used to receive commands from the central server. The vulnerability was identified in November but was not fixed until now. During the 'restartcheck' operation, substitution may be possible […]
