USN-7181-1: Salt vulnerability
Published Jan 6, 2025
·Updated
It was discovered that Salt incorrectly handled web requests when the SSH client was enabled. An attacker could possibly use this issue to achieve remote code execution or obtain sensitive information.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/salt-common<0.17.5+ds-1ubuntu0.1~esm4
0.17.5+ds-1ubuntu0.1~esm4
Ubuntu Ubuntu=14.04
All of the following
ubuntu/salt-master<0.17.5+ds-1ubuntu0.1~esm4
0.17.5+ds-1ubuntu0.1~esm4
Ubuntu Ubuntu=14.04
All of the following
ubuntu/salt-minion<0.17.5+ds-1ubuntu0.1~esm4
0.17.5+ds-1ubuntu0.1~esm4
Ubuntu Ubuntu=14.04
All of the following
ubuntu/salt-ssh<0.17.5+ds-1ubuntu0.1~esm4
0.17.5+ds-1ubuntu0.1~esm4
Ubuntu Ubuntu=14.04
All of the following
ubuntu/salt-syndic<0.17.5+ds-1ubuntu0.1~esm4
0.17.5+ds-1ubuntu0.1~esm4
Ubuntu Ubuntu=14.04
Event History
Jan 6, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7181-1?
USN-7181-1 is classified as a security vulnerability that can lead to remote code execution or exposure of sensitive information.
2
How do I fix USN-7181-1?
To fix USN-7181-1, update the affected packages to version 0.17.5+ds-1ubuntu0.1~esm4.
3
Which versions of Ubuntu are affected by USN-7181-1?
USN-7181-1 affects Ubuntu 14.04 with the specified Salt package versions.
4
What components are impacted by USN-7181-1?
USN-7181-1 impacts the Salt common, master, minion, ssh, and syndic packages.
5
What potential risks does USN-7181-1 pose?
The risks associated with USN-7181-1 include remote code execution and unauthorized access to sensitive information.