Bug 1289109 (CVE-2015-8034) - CVE-2015-8034 salt: Information leak from state.sls cache data stored as world-readable
Summary: CVE-2015-8034 salt: Information leak from state.sls cache data stored as worl...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2015-8034
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1289110 1289111
Blocks: 1289115
TreeView+ depends on / blocked
 
Reported: 2015-12-07 13:17 UTC by Adam Mariš
Modified: 2019-09-29 13:40 UTC (History)
5 users (show)

Fixed In Version: salt 2015.8.3
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-02-15 04:30:17 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2015-12-07 13:17:14 UTC
It was found that state.sls function stores state run cache on the minion onto the disk with incorrect permissions, making it world-readable. This file could potentially contain sensitive data that was inserted via jinja into the state SLS files.

Upstream bug report:

https://github.com/saltstack/salt/issues/28455

Upstream patch:

https://github.com/cachedout/salt/commit/097838ec0c52b1e96f7f761e5fb3cd7e79808741

Comment 1 Adam Mariš 2015-12-07 13:17:48 UTC
Created salt tracking bugs for this issue:

Affects: fedora-all [bug 1289110]
Affects: epel-all [bug 1289111]

Comment 2 Erik Johnson 2016-01-25 16:59:55 UTC
The 2015.5.9 builds currently in testing include this patch already.

Comment 3 Erik Johnson 2016-01-25 17:02:03 UTC
Actually, the 2015.5.8 builds in stable also include this patch, so I'm going to close this.

Comment 4 Siddharth Sharma 2016-01-25 18:58:15 UTC
(In reply to Erik Johnson from comment #3)
> Actually, the 2015.5.8 builds in stable also include this patch, so I'm
> going to close this.

Please do not close CVE bugs, these bugs are supposed to be closed by Red Hat's Product Security after the issue is fixed in all its products.

Thanks

Comment 5 Erik Johnson 2016-01-25 19:05:40 UTC
OK, but the issue *is* fixed. 2015.5.8 is in stable. What is the path to getting this issue closed, then, since I didn't add the bug number when I submitted the 2015.5.8 builds to bodhi?

I did add this bug to the 2015.5.9 builds of Salt currently in testing, before I realized that the issue was already resolved in 2015.5.8.

Comment 6 Fedora Update System 2016-02-05 00:21:41 UTC
salt-2015.5.9-2.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.