Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 836365 (CVE-2022-22934, CVE-2022-22935, CVE-2022-22936, CVE-2022-22941) - <app-admin/salt-{3002.7,3003.3}: multiple vulnerabilities
Summary: <app-admin/salt-{3002.7,3003.3}: multiple vulnerabilities
Status: IN_PROGRESS
Alias: CVE-2022-22934, CVE-2022-22935, CVE-2022-22936, CVE-2022-22941
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa?]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-03-29 09:36 UTC by Imran Iqbal
Modified: 2022-08-14 16:07 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Imran Iqbal 2022-03-29 09:36:47 UTC
This security issue was first reported on 2022-03-22:

* https://saltproject.io/security_announcements/attention-some-critical-vulnerabilities-have-been-discovered-in-salt-versions-3004-and-earlier/

The new versions were released yesterday (2022-03-28):

* https://saltproject.io/security_announcements/salt-security-advisory-release/

> Updated packages for the versions below can be found at https://repo.saltproject.io for these supported versions of Salt:
> 
> * 3004.1
> * 3003.4
> * 3002.8
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-29 14:54:51 UTC
Thanks for reporting! Is there a mailing list or something where these are announced?

Maintainer, please stabilize 3002.7 and 3003.3.
Comment 2 Imran Iqbal 2022-03-29 16:23:36 UTC
> Is there a mailing list or something where these are announced?

Yes, there are a variety of places.

* https://groups.google.com/g/salt-announce
  - This group is mainly announcements for all new releases.
* https://saltproject.io/security_announcements/
  - This is the main page for security leases (and info).
  - This can be tracked using its RSS feed:
    + https://saltproject.io/feed/?post_type=security
* https://app.slack.com/client/T7KPDM7M3/CNZKJMQ1E
  - Probably not so helpful here but there's also the `#announcements` channel on the community Slack instance.
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-31 02:48:07 UTC
(In reply to Imran Iqbal from comment #2)
> > Is there a mailing list or something where these are announced?
> 
> Yes, there are a variety of places.
> 
> * https://groups.google.com/g/salt-announce
>   - This group is mainly announcements for all new releases.
> * https://saltproject.io/security_announcements/
>   - This is the main page for security leases (and info).
>   - This can be tracked using its RSS feed:
>     + https://saltproject.io/feed/?post_type=security
> * https://app.slack.com/client/T7KPDM7M3/CNZKJMQ1E
>   - Probably not so helpful here but there's also the `#announcements`
> channel on the community Slack instance.

Thanks! Should be subscribed to that Google Group now, so I shouldn't miss these in the future.