Safety vulnerability ID: 41922
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Salt versions 3002.7 and 3003.3 include a fix for CVE-2021-22004: An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.
Latest version: 3007.1
Portable, distributed, remote execution and configuration management system
========================
Fixed
-----
- Verify the owner of an existing config before trusting it during install. If the owner cannot be verified, back it up and use defaults. (CVE-2021-22004)
Security
--------
- Fix the CVE-2021-31607 vulnerability
Additionally, an audit and a tool was put in place, ``bandit``, to address similar issues througout the code base, and prevent them. (CVE-2021-31607)
- Ensure that sourced file is cached using its hash name (cve-2021-21996)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application