From c77785846af50970f4d6c69234d1a9d2a4e0020b Mon Sep 17 00:00:00 2001 From: Frode Gundersen Date: Tue, 1 Dec 2020 10:50:49 -0700 Subject: [PATCH] Update 3000.6 release --- doc/topics/releases/3000.6.rst | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/doc/topics/releases/3000.6.rst b/doc/topics/releases/3000.6.rst index 86d98db8abb1..11c596cb3871 100644 --- a/doc/topics/releases/3000.6.rst +++ b/doc/topics/releases/3000.6.rst @@ -1,15 +1,12 @@ -.. _release-3000-5: +.. _release-3000-6: =========================== -Salt 3000.5 Release Notes +Salt 3000.6 Release Notes =========================== -Version 3000.5 is a CVE fix release for :ref:`3000 `. +Version 3000.6 is a bugfix release for :ref:`3000 `. Fixed ----- -- CVE-2020-16804 - Properly validate eauth credentials and tokens along with - their ACLs. Prior to this change eauth was not properly validated when calling - Salt ssh via the salt-api. Any value for 'eauth' or 'token' would allow a user - to bypass authentication and make calls to Salt ssh. (CVE-2020-25592) +- Fixes salt-ssh authentication when using tty (#58922)