CVE-2019-18897
published 2020-03-02CVE-2019-18897: A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.39%
30.7th percentile
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 2019.2.0-6.21.1 and prior versions. openSUSE Factory salt-master version 2019.2.2-3.1 and prior versions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | factory | salt-master – 2019.2.2-3.1 | — |
| opensuse | leap | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | suse_linux_enterprise_server_12 | salt-master – 2019.2.0-46.83.1 | — |
| suse | suse_linux_enterprise_server_15 | salt-master – 2019.2.0-6.21.1 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
salt: symlink following in salt allows for privilege escalalation
vendor_redhat·2019-11-21·CVSS 8.4
CVE-2019-18897 [HIGH] CWE-59 salt: symlink following in salt allows for privilege escalalation
salt: symlink following in salt allows for privilege escalalation
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 2019.2.0-6.21.1 and prior versions. openSUSE Factory salt-master version 2019.2.2-3.1 and prior versions.
A flaw was found in salt. A UNIX Symbolic Link (Symlink) Following vulnerability in some implementations of Linux servers allows local attackers to escalate privileges from user salt to root.
Statement: Privilege escalation is d
GHSA
GHSA-p48p-8wh6-cj6f: A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; o
ghsa_unreviewed·2022-05-24
CVE-2019-18897 [HIGH] CWE-59 GHSA-p48p-8wh6-cj6f: A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; o
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 2019.2.0-6.21.1 and prior versions. openSUSE Factory salt-master version 2019.2.2-3.1 and prior versions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation [fedora-all]
bugzilla·2020-03-06·CVSS 8.4
CVE-2019-18897 [HIGH] CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation [fedora-all]
CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation [epel-all]
bugzilla·2020-03-06·CVSS 8.4
CVE-2019-18897 [HIGH] CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation [epel-all]
CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation
bugzilla·2020-03-06·CVSS 8.4
CVE-2019-18897 [HIGH] CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation
CVE-2019-18897 salt: symlink following in salt allows for privilege escalalation
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt in some implementations of Linux servers allows local attackers to escalate privileges from user salt to root.
Discussion:
Created salt tracking bugs for this issue:
Affects: epel-all [bug 1810992]
Affects: fedora-all [bug 1810991]
---
External Reference:
https://bugzilla.suse.com/show_bug.cgi?id=1157465
---
Statement:
Privilege escalation is due to no symlink validation check in %post script for "salt-master" where file ownership is changed to salt user. salt-master was used by Red Hat Storage Console 2 which has reached End Of Life. Red Hat Ceph Storage 2 does not use salt-master, in addition affected code is not includ
2020-03-02
Published