[BUG] 3002.5 pkgrepo.managed accepts insecure key_url #59786
Labels
Bug
broken, incorrect, or confusing behavior
debian
affects this operating system
severity-critical
top severity, seen by most users, serious issues
Sulfur v3006.0
release code name and version
ubuntu
affects this operating system
Milestone
Description
From https://wiki.debian.org/DebianRepository/UseThirdParty
From https://docs.saltproject.io/en/3002/ref/states/all/salt.states.pkgrepo.html#salt.states.pkgrepo.managed
Setup
Expected behavior
Salt should refuse to download keys over HTTP by default. It's possibly acceptable to allow forcing it, but that should trigger warnings.
Versions Report
salt --versions-report
Additional context
This would probably qualify as a CVE.
The text was updated successfully, but these errors were encountered: