Blog
Saltstack RCE and vBulletin "incorrect access control" Vulnerabilities
Tue, 06/02/2020
Saltstack Remote Code Execution (RCE) Vulnerability
For those that have implemented SaltStack in your cloud environment, please be aware of several vulnerabilities (CVE-2020-11651/CVE-2020-11652) that together allow a RCE condition, which could allow an attacker to take over your Master Salt server and then laterally move to your Salt minions. Please consider patching with release 3000.2 or...