CVE-2021-25281

saltstack/salt
on github

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
7.5 HIGH

Description

An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2019.2.0 (including)2019.2.5*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.3.7 (including)2016.3.8*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.11.7 (including)2016.11.10*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.3.5 (including)2016.3.6*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2015.8.11 (including)2015.8.13*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.3.0 (including)2016.3.4*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*n/a2015.8.10*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.3.9 (including)2016.11.3*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.11.4 (including)2016.11.5*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2017.5.0 (including)2017.7.8*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2018.2.0 (including)2018.3.5 (including)*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2019.2.6 (including)2019.2.8*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*3000 (including)3000.6*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*3001 (including)3001.4*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*3002 (including)3002.5*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*n/an/a32
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*n/an/a33
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*n/an/a34
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*n/an/a9.0
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*n/an/a11.0

External Links