diff --git a/CHANGELOG.md b/CHANGELOG.md index b92e95997fb8..57cfecd551fe 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,24 @@ Versions are `MAJOR.PATCH`. # Changelog +Salt 3004.2 (2022-05-12) +======================== + +Fixed +----- + +- Expand environment variables in the root_dir registry key (#61445) +- Update Markup and contextfunction imports for jinja versions >=3.1. (#61848) +- Fix bug in tcp transport (#61865) +- Make sure the correct key is being used when verifying or validating communication, eg. when a Salt syndic is involved use syndic_master.pub and when a Salt minion is involved use minion_master.pub. (#61868) + + +Security +-------- + +- Fixed PAM auth to reject auth attempt if user account is locked. (cve-2022-22967) + + Salt 3004.1 (2022-02-16) ======================== diff --git a/changelog/61445.fixed b/changelog/61445.fixed deleted file mode 100644 index 5500608aef0e..000000000000 --- a/changelog/61445.fixed +++ /dev/null @@ -1 +0,0 @@ -Expand environment variables in the root_dir registry key diff --git a/changelog/61848.fixed b/changelog/61848.fixed deleted file mode 100644 index e8e6fd34262c..000000000000 --- a/changelog/61848.fixed +++ /dev/null @@ -1 +0,0 @@ -Update Markup and contextfunction imports for jinja versions >=3.1. diff --git a/changelog/61865.fixed b/changelog/61865.fixed deleted file mode 100644 index 2e994bcda487..000000000000 --- a/changelog/61865.fixed +++ /dev/null @@ -1 +0,0 @@ -Fix bug in tcp transport diff --git a/changelog/61868.fixed b/changelog/61868.fixed deleted file mode 100644 index 0169c48e99d2..000000000000 --- a/changelog/61868.fixed +++ /dev/null @@ -1 +0,0 @@ -Make sure the correct key is being used when verifying or validating communication, eg. when a Salt syndic is involved use syndic_master.pub and when a Salt minion is involved use minion_master.pub. diff --git a/changelog/cve-2022-22967.security b/changelog/cve-2022-22967.security deleted file mode 100644 index 52943680f448..000000000000 --- a/changelog/cve-2022-22967.security +++ /dev/null @@ -1 +0,0 @@ -Fixed PAM auth to reject auth attempt if user account is locked. diff --git a/doc/man/salt-api.1 b/doc/man/salt-api.1 index fa9c708c7837..ad179ebc87f9 100644 --- a/doc/man/salt-api.1 +++ b/doc/man/salt-api.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-API" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-API" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-api \- salt-api Command . diff --git a/doc/man/salt-call.1 b/doc/man/salt-call.1 index a0aadbdb8ba3..baa2527310cc 100644 --- a/doc/man/salt-call.1 +++ b/doc/man/salt-call.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-CALL" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-CALL" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-call \- salt-call Documentation . diff --git a/doc/man/salt-cloud.1 b/doc/man/salt-cloud.1 index b12faa75d186..7bc7ea020b47 100644 --- a/doc/man/salt-cloud.1 +++ b/doc/man/salt-cloud.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-CLOUD" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-CLOUD" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-cloud \- Salt Cloud Command . diff --git a/doc/man/salt-cp.1 b/doc/man/salt-cp.1 index debd293f2be6..249b311c4778 100644 --- a/doc/man/salt-cp.1 +++ b/doc/man/salt-cp.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-CP" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-CP" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-cp \- salt-cp Documentation . diff --git a/doc/man/salt-key.1 b/doc/man/salt-key.1 index 25f364a3c159..b5769e92e50e 100644 --- a/doc/man/salt-key.1 +++ b/doc/man/salt-key.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-KEY" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-KEY" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-key \- salt-key Documentation . diff --git a/doc/man/salt-master.1 b/doc/man/salt-master.1 index e3251582714f..3169db7bb518 100644 --- a/doc/man/salt-master.1 +++ b/doc/man/salt-master.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-MASTER" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-MASTER" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-master \- salt-master Documentation . diff --git a/doc/man/salt-minion.1 b/doc/man/salt-minion.1 index b25bf8d86762..25eeb950eaa6 100644 --- a/doc/man/salt-minion.1 +++ b/doc/man/salt-minion.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-MINION" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-MINION" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-minion \- salt-minion Documentation . diff --git a/doc/man/salt-proxy.1 b/doc/man/salt-proxy.1 index 740f441ecfe4..01ebb8726106 100644 --- a/doc/man/salt-proxy.1 +++ b/doc/man/salt-proxy.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-PROXY" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-PROXY" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-proxy \- salt-proxy Documentation . diff --git a/doc/man/salt-run.1 b/doc/man/salt-run.1 index da5985e2ad26..1d65a41209af 100644 --- a/doc/man/salt-run.1 +++ b/doc/man/salt-run.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-RUN" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-RUN" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-run \- salt-run Documentation . diff --git a/doc/man/salt-ssh.1 b/doc/man/salt-ssh.1 index ae34c6ea7129..ff81e43f0a83 100644 --- a/doc/man/salt-ssh.1 +++ b/doc/man/salt-ssh.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-SSH" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-SSH" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-ssh \- salt-ssh Documentation . diff --git a/doc/man/salt-syndic.1 b/doc/man/salt-syndic.1 index 5ccb6fb3a603..84d6d42d59f1 100644 --- a/doc/man/salt-syndic.1 +++ b/doc/man/salt-syndic.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-SYNDIC" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-SYNDIC" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-syndic \- salt-syndic Documentation . diff --git a/doc/man/salt-unity.1 b/doc/man/salt-unity.1 index 80fa599916c2..642e266f59e2 100644 --- a/doc/man/salt-unity.1 +++ b/doc/man/salt-unity.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT-UNITY" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT-UNITY" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt-unity \- salt-unity Command . diff --git a/doc/man/salt.1 b/doc/man/salt.1 index 108d38ac0943..2d97b1b7a802 100644 --- a/doc/man/salt.1 +++ b/doc/man/salt.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME salt \- salt . diff --git a/doc/man/salt.7 b/doc/man/salt.7 index 618c63080eda..c7dd9e110abd 100644 --- a/doc/man/salt.7 +++ b/doc/man/salt.7 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SALT" "7" "Feb 16, 2022" "3004.1" "Salt" +.TH "SALT" "7" "May 12, 2022" "3004.2" "Salt" .SH NAME salt \- Salt Documentation . diff --git a/doc/man/spm.1 b/doc/man/spm.1 index d0f9e78929bf..f5be1daf70aa 100644 --- a/doc/man/spm.1 +++ b/doc/man/spm.1 @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . -.TH "SPM" "1" "Feb 16, 2022" "3004.1" "Salt" +.TH "SPM" "1" "May 12, 2022" "3004.2" "Salt" .SH NAME spm \- Salt Package Manager Command . diff --git a/doc/topics/releases/3004.2.rst b/doc/topics/releases/3004.2.rst new file mode 100644 index 000000000000..bc7909f21cdd --- /dev/null +++ b/doc/topics/releases/3004.2.rst @@ -0,0 +1,20 @@ +.. _release-3004-2: + +========================= +Salt 3004.2 Release Notes +========================= + +Version 3004.2 is a CVE security fix release for :ref:`3004 `. + +Fixed +----- + +- Expand environment variables in the root_dir registry key (#61445) +- Update Markup and contextfunction imports for jinja versions >=3.1. (#61848) +- Fix bug in tcp transport (#61865) +- Make sure the correct key is being used when verifying or validating communication, eg. when a Salt syndic is involved use syndic_master.pub and when a Salt minion is involved use minion_master.pub. (#61868) + +Security +-------- + +- Fixed PAM auth to reject auth attempt if user account is locked. (cve-2022-22967)