SaltStack Shell Injection

Nash N Sulthan
Published on
16 Jun 2021

SaltStack is a configuration management and orchestration tool that is also known as Salt. A critical vulnerability was observed in SaltStack where shell injection can be initiated by sending maliciously tailored web requests to the Salt API, keeping the SSH client enabled. This can easily be exploited by an unauthenticated user with network access to the Salt API.

Mitigation / Precaution

In order to patch this vulnerability, please install the official patch SaltStack made available for supported, vulnerable instances.

Automated human-like penetration testing for your web apps & APIs
Teams using Beagle Security are set up in minutes, embrace release-based CI/CD security testing and save up to 65% with timely remediation of vulnerabilities. Sign up for a free account to see what it can do for you.

Written by
Nash N Sulthan
Nash N Sulthan
Cyber Security Lead Engineer
Find website security issues in a flash
Improve your website's security posture with proactive vulnerability detection.
Free website security assessment