请速升级Salt至3000.2版本(修复CVE-2020-11651)

18 views
Skip to first unread message

中国SaltStack用户组

unread,
Apr 30, 2020, 2:48:04 AM4/30/20
to 中国SaltStack用户组
 近期Salt出现重大安全漏洞(CVE-2020-11651), 3000.2版本以前的版本均存在该漏洞,官方已经修复该漏洞,建议尽快升级到3000.2版本。
如果无法升级到3000.2,请参考 https://github.com/saltstack/salt/commit/ffea7ffa215313f68b42f82984b0441e1017330c 进行手动打patch操作 


漏洞详情:

 The salt-master process ClearFuncs class does not properly validate method calls.
This allows a remote user to access some methods without authentication.
 
These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.


Reply all
Reply to author
Forward
0 new messages