CVE-2019-17361: Command Injection
In SaltStack Salt before 2019.2.3, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
Other sources
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/saltto a version that resolves this vulnerability.Fixed in 2019.2.3+dfsg1-1Fixed in 2018.3.4+dfsg1-6+deb10u1Fixed in 2016.11.2+ds-1+deb9u3 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2019.2.3 - Upgrade
Upgrade
SaltStack Salt (salt-api NET API with ssh client enabled)to a version that resolves this vulnerability.Fixed in 2019.2.3 - Configuration
Disable the ssh client in the salt-api NET API if it is enabled, to avoid the command injection path.
salt-api (NET API) ssh client enabled = disable
Event History
Frequently Asked Questions
What is CVE-2019-17361?
CVE-2019-17361 is a vulnerability in SaltStack Salt through 2019.2.0 that allows an unauthenticated attacker to execute arbitrary code on the salt-api host.
How severe is CVE-2019-17361?
CVE-2019-17361 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2019-17361?
SaltStack Salt versions 2019.2.0 and below are affected by CVE-2019-17361.
How can I fix CVE-2019-17361?
To fix CVE-2019-17361, upgrade to SaltStack Salt version 2019.2.3 or apply the relevant patches provided by the vendor.
Where can I find more information about CVE-2019-17361?
You can find more information about CVE-2019-17361 in the official SaltStack documentation, SaltStack GitHub repository, and the opensuse-security-announce mailing list.