CVE-2020-28972: Medium severity saltstack vulnerability
In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.
Other sources
In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-28972?
CVE-2020-28972 is a vulnerability in SaltStack Salt that allows authentication to VMware vcenter, vsphere, and esxi servers without validating the SSL/TLS certificate.
How severe is CVE-2020-28972?
CVE-2020-28972 has a severity rating of 5.9 (medium).
Which software versions are affected by CVE-2020-28972?
The affected software versions include SaltStack Salt 2018.3.4 and later, and SaltStack Salt 3002.6 and later.
How can I fix CVE-2020-28972?
To fix CVE-2020-28972, update your SaltStack Salt installation to version 3002.5 or later.
Where can I find more information about CVE-2020-28972?
You can find more information about CVE-2020-28972 at the following references: [Reference 1](https://lists.debian.org/debian-lts-announce/2021/11/msg00009.html), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVB/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUGLOJ6NXLCIFRD2JTXBYQEMAEF2B6XH/)