Security Announcements
Active Salt CVE Update - CVE-2020-11651 and CVE-2020-11652
We have created and made patches available for a number of Salt releases. Some patches are specific to certain Salt versions and, as noted, some will patch multiple versions. To ensure the patch is effective, verify installation of your version prior to installing any patches.
Active Salt CVE Update for CVE-2020-11651 and CVE-2020-11652
Last week a critical vulnerability was discovered affecting Salt Master versions 2019.2.3 and 3000.1 and earlier. SaltStack customers and Salt users who have followed fundamental internet security guidelines and best practices are not affected by this vulnerability. The vulnerability is easily exploitable if a Salt Master is exposed to the open internet.
Salt CVE Critical Updates - 2020-APR-21
We have decided to proceed with release packages for 2019.2.5 and 3000.3 that contain fixes to these new these critical CVEs (CVE-2020-11651 and CVE-2020-11652). The packages will be available Wednesday, May 13, or potentially sooner.