Back

HIGH

salt: Privilege escalation on a minion when an unprivileged user is able to create files in any non-blacklisted directory

Published Feb 27, 2021

Description

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

Affected products

Remediation

Red Hat statement

Salt has been deprecated as of Red Hat Ceph Storage 2.5, as Salt was used to install RHSCON-2 and RHSCON-2 has reached End Of Life.

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 27, 2021
Updated Aug 4, 2024
Reserved Nov 6, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 25, 2021
GHSA-PHHW-3WC9-8Q75