CVE-2023-20897
Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.
02 / AFFECTED SOFTWARE
Affected packages
60 explicit affected versions
213 explicit affected versions
216 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.
Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.
Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/20xxx/CVE-2023-20897.json
- https://lists.fedoraproject.org/archives/list/[email protected]/message/OMWJIHQZXHK6FH2E3IWAZCYIRI7FLVOL/
- https://nvd.nist.gov/vuln/detail/CVE-2023-20897
- https://saltproject.io/security-announcements/2023-08-10-advisory/
- https://github.com/advisories/GHSA-vpjg-wmf8-29h9
- https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2023-166.yaml
- https://github.com/saltstack/salt
- https://lists.fedoraproject.org/archives/list/[email protected]/message/OMWJIHQZXHK6FH2E3IWAZCYIRI7FLVOL
- https://saltproject.io/security-announcements/2023-08-10-advisory