PT-2023-24655 · Salt-Ssh+3 · Salt-Ssh+3
CVE-2023-34049
·
Publicado
2023-01-01
·
Atualizado
2026-07-07
CVSS v3.1
6.7
Média
| Vetor | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Salt-SSH (affected versions not specified)
Description
The issue concerns a predictable script path in the Salt-SSH pre-flight option, allowing an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight script before it runs, they can ensure Salt-SSH runs their script with the privileges of the user running Salt-SSH. This could lead to privilege escalation.
Recommendations
To resolve the issue, do not make the copy path on the target predictable and ensure that return codes of the scp command are checked if the copy fails. As a temporary workaround, consider restricting access to the Salt-SSH pre-flight option until a more secure configuration can be implemented. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Red Os
Salt-Ssh
Suse