VDB
KO

PYSEC-2022-210

Details

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / salt
Introduced in: 0 Fixed in: 3002.9
Fix pip install --upgrade 'salt>=3002.9'

References