SaltStack Shell Injection

Published on 16 Jun 2021
Vulnerability

SaltStack is a configuration management and orchestration tool that is also known as Salt. A critical vulnerability was observed in SaltStack where shell injection can be initiated by sending maliciously tailored web requests to the Salt API, keeping the SSH client enabled. This can easily be exploited by an unauthenticated user with network access to the Salt API.

Mitigation / Precaution

In order to patch this vulnerability, please install the official patch SaltStack made available for supported, vulnerable instances.

Nash N Sulthan
Written by
Cyber Security Lead Engineer

Nash is a seasoned Security Engineer who brings a multifaceted approach to safeguarding digital environments. Not only does he excel in implementing robust security measures, but he's also deeply involved in the research and development process, constantly innovating to stay ahead of cyber threats. Nash's commitment to security extends beyond the conventional, making him a valuable contributor to the evolving landscape of digital defense.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo