CVE-2023-34049: Salt security advisory release - 2023-OCT-27
The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script.
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2023-34049?
CVE-2023-34049 has a high severity level due to the potential for an attacker to run arbitrary scripts on the target system.
How do I fix CVE-2023-34049?
To fix CVE-2023-34049, upgrade Salt to version 3005.4 or 3006.4, as these versions contain the necessary security patch.
What impact does CVE-2023-34049 have on affected systems?
CVE-2023-34049 allows attackers to execute their scripts on compromised systems, which can lead to unauthorized access or data manipulation.
Which versions of Salt are affected by CVE-2023-34049?
CVE-2023-34049 affects Salt versions up to and including 3005.4 and 3006.4.
Is CVE-2023-34049 exploitable remotely?
Yes, CVE-2023-34049 is exploitable remotely if the Salt-SSH pre-flight option is enabled.