Bug 2237511 (CVE-2023-20898) - CVE-2023-20898 salt: Git Providers can read from the wrong environment
Summary: CVE-2023-20898 salt: Git Providers can read from the wrong environment
Keywords:
Status: NEW
Alias: CVE-2023-20898
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2237512
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-09-05 19:30 UTC by Patrick Del Bello
Modified: 2023-09-05 19:31 UTC (History)
0 users

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Patrick Del Bello 2023-09-05 19:30:58 UTC
Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that uses Git Providers with different environments can get garbage data or the wrong data, which can lead to wrongful data disclosure, wrongful executions, data corruption and/or crash.


https://saltproject.io/security-announcements/2023-08-10-advisory/

Comment 1 Patrick Del Bello 2023-09-05 19:31:12 UTC
Created salt tracking bugs for this issue:

Affects: fedora-all [bug 2237512]


Note You need to log in before you can comment on or make changes to this bug.