CVE Vulnerabilities

CVE-2020-35662

Improper Certificate Validation

Published: Feb 27, 2021 | Modified: Oct 15, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
7.4 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM

In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Salt Saltstack * 2015.8.10 (excluding)
Salt Saltstack 2015.8.11 (including) 2015.8.13 (excluding)
Salt Saltstack 2016.3.0 (including) 2016.3.4 (excluding)
Salt Saltstack 2016.3.5 (including) 2016.3.6 (excluding)
Salt Saltstack 2016.3.7 (including) 2016.3.8 (excluding)
Salt Saltstack 2016.3.9 (including) 2016.11.3 (excluding)
Salt Saltstack 2016.11.4 (including) 2016.11.5 (excluding)
Salt Saltstack 2016.11.7 (including) 2016.11.10 (excluding)
Salt Saltstack 2017.5.0 (including) 2017.7.8 (excluding)
Salt Saltstack 2018.2.0 (including) 2018.3.5 (including)
Salt Saltstack 2019.2.0 (including) 2019.2.5 (excluding)
Salt Saltstack 2019.2.6 (including) 2019.2.8 (excluding)
Salt Saltstack 3000 (including) 3000.6 (excluding)
Salt Saltstack 3001 (including) 3001.4 (excluding)
Salt Saltstack 3002 (including) 3002.5 (excluding)
Salt Ubuntu bionic *
Salt Ubuntu esm-apps/bionic *
Salt Ubuntu esm-apps/xenial *
Salt Ubuntu groovy *
Salt Ubuntu hirsute *
Salt Ubuntu impish *
Salt Ubuntu kinetic *
Salt Ubuntu trusty *
Salt Ubuntu trusty/esm *
Salt Ubuntu xenial *

Potential Mitigations

References