CVE-2020-25592: Input Validation
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
Other sources
In SaltStack the salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
— GitHub
Properly validate eauth credentials and tokens along with their Access Control Lists – ACLs. Prior to this change, eauth was not properly validated when calling Salt SSH via the salt-api. Any value for “eauth” or “token” would allow a user to bypass authentication and make calls to Salt SSH.
— Salt Project
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-25592?
CVE-2020-25592 is a vulnerability in SaltStack Salt that allows an attacker to bypass authentication and invoke Salt SSH.
What is the severity of CVE-2020-25592?
CVE-2020-25592 has a severity rating of 9.8 / 10, which is considered critical.
Which versions of SaltStack Salt are affected by CVE-2020-25592?
SaltStack Salt versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1, and 3004.1+dfsg-2.2 are affected by CVE-2020-25592.
How can an attacker exploit CVE-2020-25592?
An attacker can exploit CVE-2020-25592 by bypassing authentication and invoking Salt SSH.
Are there any remedies available for CVE-2020-25592?
Yes, SaltStack has released fixes for CVE-2020-25592. Please refer to the official SaltStack documentation for more information on how to apply the fixes.