Attackers Exploit Two Vulnerabilities in SaltStack to Publish Arbitrary Control Messages and Much More

From ehackingnews.com

CISA has sent warnings to the users regarding two critical vulnerabilities in SaltStack Salt, an open-source remote task and configuration management framework that has been actively exploited by cybercriminals, leaving around thousands of cloud servers across the globe exposed to the threat.

The vulnerabilities that are easy to exploit are of high-severity and researchers have labeled them as particularly ‘dangerous’. It allows attackers to execute code remotely with root privileges on Salt master repositories to carry out a number of commands.

Read more…