Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.
References
Configurations
Configuration 1 (hide)
|
History
13 Feb 2025, 17:16
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted. |
21 Nov 2024, 07:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OMWJIHQZXHK6FH2E3IWAZCYIRI7FLVOL/ - | |
References | () https://saltproject.io/security-announcements/2023-08-10-advisory/ - Vendor Advisory |
14 Sep 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Sep 2023, 19:40
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CWE | CWE-404 | |
CPE | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | |
First Time |
Saltstack salt
Saltstack |
|
References | (MISC) https://saltproject.io/security-announcements/2023-08-10-advisory/ - Vendor Advisory |
05 Sep 2023, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-05 11:15
Updated : 2025-02-13 17:16
NVD link : CVE-2023-20897
Mitre link : CVE-2023-20897
CVE.ORG link : CVE-2023-20897
JSON object : View
Products Affected
saltstack
- salt
CWE
CWE-404
Improper Resource Shutdown or Release