Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 607824 (CVE-2017-5192, CVE-2017-5200) - <app-admin/salt-{2015.8.13,2016.3.5,2016.11.2}: multiple vulnerabilities
Summary: <app-admin/salt-{2015.8.13,2016.3.5,2016.11.2}: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2017-5192, CVE-2017-5200
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://docs.saltstack.com/en/latest/...
Whiteboard: ~2 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-01-31 16:16 UTC by Thomas Deutschmann (RETIRED)
Modified: 2017-10-27 19:03 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-31 16:16:13 UTC
Salt 2016.11.2 is a security release. The following CVEs were fixed as part of this release:

CVE-2017-5192: local_batch client external authentication not respected

The `LocalClient.cmd_batch()` method client does not accept `external_auth` credentials and so access to it from salt-api has been removed for now. This vulnerability allows code execution for already-authenticated users and is only in effect when running salt-api as the `root` user.


CVE-2017-5200: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client

Users of Salt-API and salt-ssh could execute a command on the salt master via a hole when both systems were enabled.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-31 16:26:32 UTC
2016.3.x also affected, 2016.3.5 now released, see https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-31 16:31:40 UTC
And now we are complete, 2015.8.x also affected, 2015.8.13 now released, see https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html
Comment 3 Patrick McLean gentoo-dev 2017-01-31 23:21:57 UTC
2016.11.2, 2016.3.5 and 2015.8.13 added to the tree and vulnerable versions removed
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-31 23:38:47 UTC
@ Maintainer(s): Thank you for the bump.

Package had no stable version, so no stabilization needed.
Repository is clean, all done.