PT-2023-36196 · Salt · Salt
Published
2023-06-21
·
Updated
2023-06-21
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
salt versions prior to 3006.0
Description
The issue is related to several problems in the salt software, including collections Mapping issues, conflicts with dependencies, and failures due to the unavailability of the transactional update module. The update to Salt release version 3006.0 fixes these issues. There is no information about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations
Update to Salt release version 3006.0 or later to fix the issues.
As a temporary workaround, consider disabling the
transactional update module until a patch is available.
Restrict access to the salt-ssh executions to minimize the risk of exploitation.
Avoid using the importlib-metadata version less than 5.0.0 in the affected API endpoint until the issue is resolved.
At the moment, there is no other information about additional mitigation measures. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Salt