First published: Sat Feb 27 2021(Updated: )
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SaltStack Salt | <2015.8.10 | |
SaltStack Salt | >=2015.8.11<2015.8.13 | |
SaltStack Salt | >=2016.3.0<2016.3.4 | |
SaltStack Salt | >=2016.3.5<2016.3.6 | |
SaltStack Salt | >=2016.3.7<2016.3.8 | |
SaltStack Salt | >=2016.3.9<2016.11.3 | |
SaltStack Salt | >=2016.11.4<2016.11.5 | |
SaltStack Salt | >=2016.11.7<2016.11.10 | |
SaltStack Salt | >=2017.5.0<2017.7.8 | |
SaltStack Salt | >=2018.2.0<=2018.3.5 | |
SaltStack Salt | >=2019.2.0<2019.2.5 | |
SaltStack Salt | >=2019.2.6<2019.2.8 | |
SaltStack Salt | >=3000<3000.6 | |
SaltStack Salt | >=3001<3001.4 | |
SaltStack Salt | >=3002<3002.5 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
SaltStack Salt | <3002.2<3001.4<3000.6<2019.2.8<2019.2.5<2018.3.5<2017.7.8<2016.11.10<2016.11.6<2016.11.5<2016.11.3<2016.3.8<2016.3.6<2016.3.4<2015.8.13<2015.8.10<3002.5<3001.6<3000.8<3002.5<3001.6<3000.8 | 3002.2 3001.4 3000.6 2019.2.8 2019.2.5 2018.3.5 2017.7.8 2016.11.10 2016.11.6 2016.11.5 2016.11.3 2016.3.8 2016.3.6 2016.3.4 2015.8.13 2015.8.10 3002.5 3001.6 3000.8 3002.5 3001.6 3000.8 |
pip/salt | >=3002<3002.3 | 3002.3 |
pip/salt | >=3001<3001.5 | 3001.5 |
pip/salt | >=3000<3000.7 | 3000.7 |
pip/salt | >=2019.2.0<2019.2.8 | 2019.2.8 |
pip/salt | >=2018.2.0<=2018.3.5 | |
pip/salt | >=2017.5.0<2017.7.8 | 2017.7.8 |
pip/salt | >=2016.11.7<2016.11.10 | 2016.11.10 |
pip/salt | >=2016.3.0<2016.11.5 | 2016.11.5 |
pip/salt | <2015.8.13 | 2015.8.13 |
debian/salt | ||
<2015.8.10 | ||
>=2015.8.11<2015.8.13 | ||
>=2016.3.0<2016.3.4 | ||
>=2016.3.5<2016.3.6 | ||
>=2016.3.7<2016.3.8 | ||
>=2016.3.9<2016.11.3 | ||
>=2016.11.4<2016.11.5 | ||
>=2016.11.7<2016.11.10 | ||
>=2017.5.0<2017.7.8 | ||
>=2018.2.0<=2018.3.5 | ||
>=2019.2.0<2019.2.5 | ||
>=2019.2.6<2019.2.8 | ||
>=3000<3000.6 | ||
>=3001<3001.4 | ||
>=3002<3002.5 | ||
=32 | ||
=33 | ||
=34 | ||
=9.0 | ||
=10.0 | ||
=11.0 |
Update the minion to the latest release, package or patch file
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35662 is a vulnerability in SaltStack Salt before version 3002.5 that allows authentication to services using certain modules without validating the SSL certificate.
The severity of CVE-2020-35662 is high, with a CVSS score of 7.4.
SaltStack Salt versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1, and 3004.1+dfsg-2.2 are affected by CVE-2020-35662.
To fix CVE-2020-35662, update SaltStack Salt to version 3002.5 or later.
You can find more information about CVE-2020-35662 at the following references: [Reference 1](https://lists.debian.org/debian-lts-announce/2021/11/msg00009.html), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVB/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUGLOJ6NXLCIFRD2JTXBYQEMAEF2B6XH/)