Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 











Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

F-Secure vulnerability research: SaltStack

April 2020 by F-Secure

F-Secure has just released new research around discovered critical vulnerabilities in the popular ‘Salt’ remote task and configuration framework. This potentially allow attackers to bypass authentication and authorization settings and take control of thousands of servers in the Cloud.

By exploiting these vulnerabilities, an attacker could execute code remotely with root privileges on the master central repository. For this reason it has been awarded the highest severity rating possible in the ‘Common Vulnerability Scoring System’.

Salt is open-source software used in infrastructure, network, and security automation solutions from a company called SaltStack and a popular tool used to maintain data centres and cloud environments. Salt frameworks consist of a “master” server which acts as a central repository and controls any number of “minion” agents that carry out tasks and collect data for the system.

The researchers also discovered 6000 Salt masters (each one controlling anything between zero to hundreds of minions) openly discoverable on the internet, which if found, can be exploited by bad actors to take control of the server with admin privileges. From there, they can carry out anything from Cryptomining, install backdoors into systems and carry out ransomware attacks.


See previous articles

    

See next articles












Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts