forked from aquasecurity/cloudsploit
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathopenSalt.js
More file actions
49 lines (39 loc) · 1.78 KB
/
Copy pathopenSalt.js
File metadata and controls
49 lines (39 loc) · 1.78 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
var async = require('async');
var helpers = require('../../../helpers/google');
module.exports = {
title: 'Open Salt',
category: 'VPC Network',
domain: 'Network Access Control',
description: 'Determine if TCP ports 4505 or 4506 for the Salt master are open to the public',
more_info: 'Active Salt vulnerabilities, CVE-2020-11651 and CVE-2020-11652 are exploiting Salt instances exposed to the internet. These ports should be closed immediately.',
link: 'https://help.saltstack.com/hc/en-us/articles/360043056331-New-SaltStack-Release-Critical-Vulnerability',
recommended_action: 'Restrict TCP ports 4505 and 4506 to known IP addresses',
apis: ['firewalls:list', 'projects:get'],
run: function(cache, settings, callback) {
var results = [];
var source = {};
var regions = helpers.regions();
async.each(regions.firewalls, function(region, rcb){
let firewalls = helpers.addSource(
cache, source, ['firewalls', 'list', region]);
if (!firewalls) return rcb();
if (firewalls.err || !firewalls.data) {
helpers.addResult(results, 3, 'Unable to query firewall rules', region, null, null, firewalls.err);
return rcb();
}
if (!firewalls.data.length) {
helpers.addResult(results, 0, 'No firewall rules found', region);
return rcb();
}
let ports = {
'tcp': [4505,4506]
};
let service = 'Salt';
helpers.findOpenPorts(firewalls.data, ports, service, region, results, cache, callback, source);
rcb();
}, function(){
// Global checking goes here
callback(null, results, source);
});
}
};