CVE-2020-35662: High severity saltstack vulnerability
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
Other sources
Several places where Salt was not verifying the SSL cert by default
— Salt Project
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-35662?
CVE-2020-35662 is a vulnerability in SaltStack Salt before version 3002.5 that allows authentication to services using certain modules without validating the SSL certificate.
What is the severity of CVE-2020-35662?
The severity of CVE-2020-35662 is high, with a CVSS score of 7.4.
Which software is affected by CVE-2020-35662?
SaltStack Salt versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1, and 3004.1+dfsg-2.2 are affected by CVE-2020-35662.
How can I fix CVE-2020-35662?
To fix CVE-2020-35662, update SaltStack Salt to version 3002.5 or later.
Where can I find more information about CVE-2020-35662?
You can find more information about CVE-2020-35662 at the following references: [Reference 1](https://lists.debian.org/debian-lts-announce/2021/11/msg00009.html), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVB/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUGLOJ6NXLCIFRD2JTXBYQEMAEF2B6XH/)