漏洞信息详情
Saltstack SaltStack Salt 注入漏洞
漏洞简介
Saltstack SaltStack Salt是SaltStack(Saltstack)公司的一套开源的用于管理基础架构的工具。该工具提供配置管理、远程执行等功能。
SaltStack Salt before 3002.5 存在注入漏洞,该漏洞源于通过在参数中包含ProxyCommand或通过API请求中提供的ssh选项,容易受到shell注入的攻击。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/
参考网址
来源:MISC
链接:https://github.com/saltstack/salt/releases
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/YOGNT2XWPOYV7YT75DN7PS4GIYWFKOK5/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/11/msg00009.html
来源:CONFIRM
链接:https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/FUGLOJ6NXLCIFRD2JTXBYQEMAEF2B6XH/
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-5011
来源:GENTOO
链接:https://security.gentoo.org/glsa/202103-01
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVB/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162038/Gentoo-Linux-Security-Advisory-202103-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021112302
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0727
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0740
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3835
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0975
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1788
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3958
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/SaltStack-multiple-vulnerabilities-34704
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0976
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-3197
受影响实体
暂无
补丁
- SaltStack Salt 命令注入漏洞的修复措施<!--2021-2-26-->
还没有评论,来说两句吧...