forked from saltstack/salt
-
Notifications
You must be signed in to change notification settings - Fork 1
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request saltstack#2 from saltstack/security-fixes
Security fix 2019.2.4
- Loading branch information
Showing
12 changed files
with
562 additions
and
16 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,24 @@ | ||
=========================== | ||
Salt 2019.2.4 Release Notes | ||
=========================== | ||
|
||
Version 2019.2.4 is a CVE-fix release for :ref:`2019.2.0 <release-2019-2-0>`. | ||
|
||
Security Fix | ||
============ | ||
|
||
**CVE-2020-11651** | ||
|
||
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. | ||
The salt-master process ClearFuncs class does not properly validate | ||
method calls. This allows a remote user to access some methods without | ||
authentication. These methods can be used to retrieve user tokens from | ||
the salt master and/or run arbitrary commands on salt minions. | ||
|
||
|
||
**CVE-2020-11652** | ||
|
||
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. | ||
The salt-master process ClearFuncs class allows access to some methods | ||
that improperly sanitize paths. These methods allow arbitrary | ||
directory access to authenticated users. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.