CVE-2020-28243: Command Injection
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Other sources
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Local Privilege Escalation in the Minion
— Salt Project
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-28243.
What is the severity of CVE-2020-28243?
CVE-2020-28243 has a severity of 7.8 (High).
How does the vulnerability in SaltStack Salt before 3002.5 manifest?
The vulnerability in SaltStack Salt before 3002.5 allows for local privilege escalation by any user able to create files on the minion in a non-blacklisted directory.
How can I fix the vulnerability in SaltStack Salt before 3002.5?
To fix the vulnerability in SaltStack Salt before 3002.5, update to version 3002.5 or later.
Where can I find more information about CVE-2020-28243?
More information about CVE-2020-28243 can be found at the following references: [link1], [link2], [link3].