Saltstack | ¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-11-04


0x00 ·ì϶¸ÅÊö

²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Saltstack

CVE-2020-16846

ºÅÁî×¢Èë

¸ßΣ

ÊÇ

SaltStack < 3002.1

SaltStack < 3001.3

SaltStack < 3000.5

SaltStack < 2019.2.7

 

 

CVE-2020-25592

ÑéÖ¤ÈÆ¹ý

¸ßΣ

ÊÇ

CVE-2020-17490

Âß¼­·ì϶

µÍΣ

ÊÇ

 

0x01 ·ì϶ÏêÇé

image.png 


SaltStackÊÇPython˵»°±àдµÄ¿ªÔ´IT»ù´¡¼Ü¹¹½â¾ö¹æ»®£¬ÏÖÒѱ»È«ÊÀ½çµÄÊý¾ÝÖÐÐÄ¿í·ºÊ¹Óá£

2020Äê11ÔÂ03ÈÕ£¬SaltStack°ä²¼°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁËÈý¸ö¹Ø¼ü·ì϶£¬ÏêÇéÈçÏ£º

SaltStackºÅÁî×¢Èë·ì϶£¨CVE-2020-16846£©

ÓµÓÐSalt APIÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄܹ»Ê¹ÓÃSSH¿Í»§¶Ëͨ¹ýSalt API½øÐÐShell×¢Èë¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÔÚSalt APIÉÏÔËÐдúÂë¡£¸Ã·ì϶¿Éͨ¹ýÔÚŲÓá°subprocess¡±Ê±É¾³ý¡°shell=True¡±Ñ¡ÏîÀ´½¨²¹£¬ÈçÏ£º

image.png

²Î¿¼Á´½Ó£º

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16846

 

SaltStackÂß¼­·ì϶£¨CVE-2020-17490£©

ÔÚTLSÖ´ÐÐÄ£¿éʹÓú¯Êýcreate_ca¡¢create_csrºÍcreate_self_signed_certʱ£¬Ëü½«ÎÞ·¨È·±£Ê¹ÓÃÕýÈ·µÄȨÏÞ´´½¨ÃÜÔ¿¡£¹¥»÷Õ߿ɵǼsaltÖ÷»ú¶ÁÈ¡µ½ÃÜÔ¿ÄÚÈÝ£¬µ¼ÖÂÐÅϢй¶¡£

²Î¿¼Á´½Ó£º

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17490

 

SaltStackÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-25592£©

SaltStackÔÚÑéÖ¤eauthÍ´´¦¼°Æä½Ó¼û½ÚÔìÁбíACLʱ´æÔÚ°²È«·ì϶¡£¹¥»÷ÕßÄܹ»Í¨¹ýsalt-apiÈÆ¹ýÉí·ÝÑéÖ¤²¢Ê¹ÓÃSSHÏνÓÖ¸±ê·þÎñÆ÷¡£ 

²Î¿¼Á´½Ó£º

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25592

 

½ØÖ¹Ä¿Ç°£¬ShodanÉϹ²ÁгöÁË6,000¶à¸ö¶³öÓÚInternetµÄSalt Master½Úµã£¬µ«²¢·ÇËùÓнڵ㶼ÊÇÔËÐеÄ×îа汾¡£

image.png

 

 

 

0x02 ´ëÖý¨Òé

ĿǰSaltstack¹Ù·½ÒѾ­°ä²¼Ð°汾£¬½¨ÒéʵʱÉý¼¶¡£

ÏÂÔØµØÖ·£º

https://repo.saltstack.com/

https://pypi.org/project/salt/#history

 

0x03 ²Î¿¼Á´½Ó

https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/

https://docs.saltstack.com/en/latest/

https://docs.saltstack.com/en/latest/topics/releases/3002.1.html

https://docs.saltstack.com/en/latest/topics/releases/3001.3.html

https://www.bleepingcomputer.com/news/security/saltstack-reveals-new-critical-vulnerabilities-patch-now/?

 

0x04 ¹¦·òÏß

2020-11-03  Saltstack°ä²¼°²È«²¼¸æ

2020-11-04  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 

image.png