Headline
Ubuntu Security Notice USN-6849-1
Ubuntu Security Notice 6849-1 - It was discovered that Salt incorrectly validated method calls and sanitized paths. A remote attacker could possibly use this issue to access some methods without authentication.
==========================================================================Ubuntu Security Notice USN-6849-1June 25, 2024salt vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 14.04 LTSSummary:Several security issues were fixed in Salt.Software Description:- salt: Infrastructure management built on a dynamic communication busDetails:It was discovered that Salt incorrectly validated method calls andsanitized paths. A remote attacker could possibly use this issue to accesssome methods without authentication. (CVE-2020-11651, CVE-2020-11652)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 14.04 LTS salt-common 0.17.5+ds-1ubuntu0.1~esm2 Available with Ubuntu Pro salt-master 0.17.5+ds-1ubuntu0.1~esm2 Available with Ubuntu Pro salt-minion 0.17.5+ds-1ubuntu0.1~esm2 Available with Ubuntu ProAfter a standard system update you need to restart Salt to make all thenecessary changes.References: https://ubuntu.com/security/notices/USN-6849-1 CVE-2020-11651, CVE-2020-11652
Related news
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application.
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application.
Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.
Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.