Showing posts with label saltstack. Show all posts
Showing posts with label saltstack. Show all posts

Tuesday, June 21, 2022

SaltStack 3004.1 Security Issue

SaltStack released an update today:
https://saltproject.io/security_announcements/salt-security-advisory-release-june-21st-2022/

Security Onion currently uses SaltStack 3004.1. However, we don't use PAM authentication from within Salt so this security issue should not affect our installations.

We do have plans to update to Salt 3004.2 in the upcoming 2.3.140 release:
https://github.com/Security-Onion-Solutions/securityonion/issues/8166


Thursday, April 7, 2022

Security Onion 2.3.110 20220407 Hotfix Now Available!

We recently released Security Onion 2.3.110 and a couple of hotfixes:
https://blog.securityonion.net/2022/03/security-onion-23110-now-available.html
https://blog.securityonion.net/2022/04/security-onion-23110-20220401-hotfix.html
https://blog.securityonion.net/2022/04/security-onion-23110-20220405-hotfix.html

Today, we are releasing a third hotfix:
https://docs.securityonion.net/en/2.3/release-notes.html#hotfix-20220407-changes

If you haven't updated recently, then you should review all links above so that you are aware of all recent changes.

If you had a previous failed soup please ensure that the salt-master service is running before you run soup again.

New Installations

If you want to perform a new installation, please review the documentation and then you can find instructions here:
https://docs.securityonion.net/en/2.3/download.html

Existing 2.3 Installations

If you have an existing 2.3 installation that you want to update, please see:
https://docs.securityonion.net/en/2.3/soup.html

Security Onion 16.04

If you are still running Security Onion 16.04, please note that it is past End Of Life. Please take this opportunity to upgrade to Security Onion 2:
https://docs.securityonion.net/en/2.3/appendix.html

Questions or Problems

If you have questions or problems, please see our community support forum guidelines:
https://docs.securityonion.net/en/2.3/community-support.html

You can then find the community support forum at:
https://securityonion.net/discuss

Monday, April 4, 2022

Security Onion 2.3.110 20220401 Hotfix Now Available!

We recently released Security Onion 2.3.110:
https://blog.securityonion.net/2022/03/security-onion-23110-now-available.html

Today, we are releasing a hotfix to update to SaltStack version 3004.1:
https://docs.securityonion.net/en/2.3/release-notes.html#hotfix-20220401-changes

If you haven't updated recently, then you should review all links above so that you are aware of all recent changes.

New Installations

If you want to perform a new installation, please review the documentation and then you can find instructions here:
https://docs.securityonion.net/en/2.3/download.html

Existing 2.3 Installations

If you have an existing 2.3 installation that you want to update, please see:
https://docs.securityonion.net/en/2.3/soup.html

Security Onion 16.04

If you are still running Security Onion 16.04, please note that it is past End Of Life. Please take this opportunity to upgrade to Security Onion 2:
https://docs.securityonion.net/en/2.3/appendix.html

Questions or Problems

If you have questions or problems, please see our community support forum guidelines:
https://docs.securityonion.net/en/2.3/community-support.html

You can then find the community support forum at:
https://securityonion.net/discuss


Friday, April 1, 2022

SaltStack Security Release Causing Security Onion Installations to Fail on Ubuntu

SaltStack has released version 3004.1:
https://docs.saltproject.io/en/latest/topics/releases/3004.1.html

SaltStack also removed version 3004 which is causing new installations of Security Onion to fail on Ubuntu. For CentOS, we host our own packages so those installations are still working properly.

We are working on a Security Onion hotfix to include SaltStack version 3004.1. We hope to release this hotfix next week.

UPDATE 2022/04/04

We've released our hotfix:
https://blog.securityonion.net/2022/04/security-onion-23110-20220401-hotfix.html

Monday, May 4, 2020

SaltStack CVE-2020-11651 and CVE-2020-11652

Two vulnerabilities in SaltStack were recently announced:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11651

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11652

In the current Security Onion 16.04 platform, we use the standard SaltStack packages from the standard Ubuntu repositories.  Ubuntu is currently tracking these as follows:

https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-11651.html

https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-11652.html

We would expect that as soon as Ubuntu updates its packages, then a standard "soup" update would completely remove the vulnerabilities.

UPDATE 2020/08/14 - Ubuntu has released updated packages:

In the meantime, please keep in mind that Security Onion locks down the host-based firewall to only allow connections to the salt ports from known good salt minions.  If you feel the need for additional compensating controls, you may wish to add firewall restrictions to your network firewalls as well.

Search This Blog

Featured Post

Security Onion 3.1.0 Hotfix 20260528 Now Available!

Last week, we released Security Onion 3.1.0: https://blog.securityonion.net/2026/05/security-onion-310-now-available-with.html Today we are ...

Popular Posts

Blog Archive