PT-2021-2354 · Suse+3 · Suse Linux Enterprise Server+4

Marcus Meissner

·

Published

2021-02-17

·

Updated

2023-06-22

·

CVE-2021-25315

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3 openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions
Description The issue is related to an improper authentication algorithm implementation in SaltStack Salt, allowing local attackers to execute arbitrary code via salt without specifying valid credentials. This can be exploited to gain unauthorized access.
Recommendations For SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3, update to version 3002.2-3 or later. For openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions, update to a version later than 3002.2-2.1. As a temporary workaround, consider restricting access to the salt functionality until a patch is applied.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1591
ALT-PU-2021-1982
ALT-PU-2022-3218
BDU:2021-01592
CVE-2021-25315
GHSA-PMJ6-9F8C-8G2M
OPENSUSE-SU-2021:0899-1
OPENSUSE-SU-2021:2106-1
OPENSUSE-SU-2021_0899-1
OPENSUSE-SU-2021_2106-1
OPENSUSE-SU-2024:11364-1
PYSEC-2021-891
SUSE-SU-2021:0914-1
SUSE-SU-2021:2104-1
SUSE-SU-2021:2105-1
SUSE-SU-2021:2106-1
SUSE-SU-2021_2104-1

Affected Products

Alt Linux
Suse Linux Enterprise Server
Saltstack Salt
Suse
Opensuse Tumbleweed