RULE(RULE ID:333415)

Rule General Information
Release Date: 2021-04-07
Rule Name: SaltStack Salt API Directory Traversal Vulnerability (CVE-2021-25282)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/162058/SaltStack-Salt-API-Unauthenticated-Remote-Command-Execution.html
https://github.com/saltstack/salt/releases
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVB/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUGLOJ6NXLCIFRD2JTXBYQEMAEF2B6XH/
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/