SaltStack Vulnerabilities SecurityOnion version 2.3.270 #11595
-
I just recently updated to version 2.3.270. This is what my Nessus scanner found. Does anyone have a fix? SaltStack 3000 < 3002.8 / 3003 < 3003.4 / 3004 < 3004.1 Multiple Vulnerabilities
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
We don't use git and we lock the salt ports down to trusted minions. In order to do anything with 2023-20897 you would need to attack from a trusted minion. The worst case scenario there is not having to restart the master service but doing IR on the trusted minion that is launching said DOS attack. Upgrading to 2.4 will get you the 3006 code. |
Beta Was this translation helpful? Give feedback.
We don't use git and we lock the salt ports down to trusted minions. In order to do anything with 2023-20897 you would need to attack from a trusted minion. The worst case scenario there is not having to restart the master service but doing IR on the trusted minion that is launching said DOS attack.
Upgrading to 2.4 will get you the 3006 code.