GLSA 202310-22: Salt: Multiple Vulnerabilities
Severity: | high |
Title: | Salt: Multiple Vulnerabilities |
Date: | 10/31/2023 |
Bugs: |
|
ID: | 202310-22 |
Synopsis
Multiple vulnerabilities have been discovered in Salt, the worst of which could result in local privilege escalation.Background
Salt is a fast, intelligent and scalable automation engine.
Affected packages
Package | Vulnerable | Unaffected | Architecture(s) |
---|---|---|---|
app-admin/salt | < 3004.2 | >= 3004.2 | All supported architectures |
Description
Multiple vulnerabilities have been discovered in Salt. Please review the CVE identifiers referenced below for details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
All Salt users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-admin/salt-3004.2"
References
CVE-2022-22967 CVE-2022-22941 CVE-2022-22936 CVE-2022-22935 CVE-2022-22934 CVE-2021-31607 CVE-2021-25284 CVE-2021-25283 CVE-2021-25282 CVE-2021-25281 CVE-2021-21996 CVE-2021-3197 CVE-2021-3148 CVE-2021-3144 CVE-2020-35662 CVE-2020-28972 CVE-2020-28243
Availability
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.
License
Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.