PT-2021-2354 · Suse+3 · Suse Linux Enterprise Server+4
Marcus Meissner
·
Published
2021-02-17
·
Updated
2023-06-22
·
CVE-2021-25315
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3
openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions
Description
The issue is related to an improper authentication algorithm implementation in SaltStack Salt, allowing local attackers to execute arbitrary code via salt without specifying valid credentials. This can be exploited to gain unauthorized access.
Recommendations
For SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3, update to version 3002.2-3 or later.
For openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions, update to a version later than 3002.2-2.1.
As a temporary workaround, consider restricting access to the salt functionality until a patch is applied.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse Linux Enterprise Server
Saltstack Salt
Suse
Opensuse Tumbleweed