Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 607824 (CVE-2017-5192, CVE-2017-5200)

Summary: <app-admin/salt-{2015.8.13,2016.3.5,2016.11.2}: multiple vulnerabilities
Product: Gentoo Security Reporter: Thomas Deutschmann (RETIRED) <whissi>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: chutzpah
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://docs.saltstack.com/en/latest/topics/releases/2016.11.2.html
Whiteboard: ~2 [noglsa cve]
Package list:
Runtime testing required: ---

Description Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-31 16:16:13 UTC
Salt 2016.11.2 is a security release. The following CVEs were fixed as part of this release:

CVE-2017-5192: local_batch client external authentication not respected

The `LocalClient.cmd_batch()` method client does not accept `external_auth` credentials and so access to it from salt-api has been removed for now. This vulnerability allows code execution for already-authenticated users and is only in effect when running salt-api as the `root` user.


CVE-2017-5200: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client

Users of Salt-API and salt-ssh could execute a command on the salt master via a hole when both systems were enabled.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-31 16:26:32 UTC
2016.3.x also affected, 2016.3.5 now released, see https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-31 16:31:40 UTC
And now we are complete, 2015.8.x also affected, 2015.8.13 now released, see https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html
Comment 3 Patrick McLean gentoo-dev 2017-01-31 23:21:57 UTC
2016.11.2, 2016.3.5 and 2015.8.13 added to the tree and vulnerable versions removed
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-31 23:38:47 UTC
@ Maintainer(s): Thank you for the bump.

Package had no stable version, so no stabilization needed.
Repository is clean, all done.