Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Salt vulnerabilities linked to incidents at LineageOS, Ghost and DigiCert were CVE-2020-11651, an authentication bypass, and CVE-2020-11652, a directory traversal. They were disclosed and exploited in 2020—not recent vulnerabilities. The Canadian Centre for Cyber Security said internet-reachable Salt master ports could let unauthorized actors exploit the flaws; Salt released fixes in May 2020.

What were the Salt vulnerabilities?

Salt is an open-source, Python-based system management framework. Salt minions connect to a central Salt master, which administrators use to manage systems. The Canadian Centre for Cyber Security (Cyber Centre) said the master listens by default on TCP ports 4505 and 4506. In 2020, it reported active exploitation and warned that a master reachable through exposed ports could be vulnerable to unauthorized access. Cyber Centre advisory, modified May 5, 2020.

  • CVE-2020-11651: an authentication bypass that allowed unauthenticated network access.
  • CVE-2020-11652: a directory traversal flaw that could allow access to the server’s filesystem.

The flaws were distinct, but together they created serious risk when an exposed Salt master could be reached by an unauthorized actor.

Which Salt versions fixed the flaws?

Salt released versions 3000.2 and 2019.2.4 to address the vulnerabilities in May 2020, according to the Cyber Centre. Those are historical fixed releases, not a recommendation to install them today. Administrators should use current Salt guidance to select a supported upgrade for their environment. The Cyber Centre also advised keeping Salt administrative ports off the public internet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What was reported at LineageOS, Ghost and DigiCert?

Sonatype’s 2020 State of the Software Supply Chain report summarized the incidents below. These are contemporaneous reports, not complete forensic accounts, and do not establish a comparable picture of each organization’s losses or lasting impact. Sonatype, 2020 State of the Software Supply Chain Report.

Organization Event reported by Sonatype
LineageOS Detected an intrusion on May 2, 2020, at about 8 p.m. Pacific time.
Ghost Reported that an attacker used a CVE in its Salt master to access infrastructure and install a cryptocurrency miner.
DigiCert Reported that one Certificate Transparency log was affected after attackers used the Salt exploits.

The report does not, by itself, substantiate further claims about signing keys, customer data, certificate issuance, or the full scope of any compromise.

How did the 2020 exposure unfold?

Sonatype’s report gives this historical chronology. Its figures describe 2020 conditions and should not be read as current exposure measurements.

  1. March 12, 2020: the report timeline says the vulnerability was found in Salt.
  2. March 24, 2020: SaltStack confirmed receipt of a vulnerability report.
  3. April 15, 2020: F-Secure informed SaltStack of 6,000 publicly exposed Salt masters at risk, as recounted by Sonatype.
  4. April 29, 2020: Sonatype’s timeline records release of versions 3000.2 and 2019.2.4 and publication of CVE-2020-11651 and CVE-2020-11652.
  5. May 2–3, 2020: the report places the LineageOS intrusion detection and Ghost miner incident in this period.
  6. May 3, 2020: DigiCert reported an affected Certificate Transparency log.
  7. May 12, 2020: Sonatype attributed to Censys a count of 2,928 Salt servers still exposed.

Sonatype’s report also reproduces a statement attributed to F-Secure: “We expect that any competent hacker will be able to create 100% reliable exploits for these issues in under 24 hours.” The report does not identify an individual speaker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should administrators secure a Salt master?

The practical measures identified by the Cyber Centre are to update Salt and restrict access to its administrative ports. For a master that may have been exposed, treat the situation as a security incident rather than assuming that patching alone resolves any prior compromise.

  • Upgrade to a currently supported Salt version, following Salt’s current release guidance; do not treat 3000.2 or 2019.2.4 as current releases.
  • Ensure TCP ports 4505 and 4506 are not exposed to unauthorized internet connections. Limit access to trusted networks and authorized systems.
  • Review whether the master was reachable by unauthorized parties and investigate suspicious activity if exposure or exploitation is suspected.

Salt’s security disclosure policy identifies its canonical security information and announcement mailing lists: Salt Project security disclosure policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.