Vulnerability Description
Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Saltstack | Salt | < 3005.2 |
Related Weaknesses (CWE)
References
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://saltproject.io/security-announcements/2023-08-10-advisory/Vendor Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://saltproject.io/security-announcements/2023-08-10-advisory/Vendor Advisory
FAQ
What is CVE-2023-20897?
CVE-2023-20897 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unrespons...
How severe is CVE-2023-20897?
CVE-2023-20897 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-20897?
Check the references section above for vendor advisories and patch information. Affected products include: Saltstack Salt.