PT-2021-6507 · Saltstack+2 · Saltstack Salt+2

Jonathan Schlue

·

Published

2020-08-25

·

Updated

2023-12-21

·

CVE-2021-21996

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SaltStack Salt versions prior to 3003.3
Description The issue is related to information disclosure in the error data area of the Salt configuration management and remote execution system. Exploitation of this issue allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. A user who has control of the source and source hash URLs can gain full file system access as root on a salt minion.
Recommendations For SaltStack Salt versions prior to 3003.3, update to version 3003.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the source and source hash URLs to minimize the risk of exploitation.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2668
ALT-PU-2020-2697
ALT-PU-2022-3218
BDU:2022-01766
CVE-2021-21996
DLA-2823-1
DLA-2823-2
DSA-5011-1
GHSA-PF7H-H2WQ-M7PG
OPENSUSE-SU-2021:1443-1
OPENSUSE-SU-2021:3557-1
OPENSUSE-SU-2021_1443-1
OPENSUSE-SU-2021_3557-1
OPENSUSE-SU-2024:11364-1
PYSEC-2021-318
SUSE-RU-2021:3551-1
SUSE-SU-2021:14833-1
SUSE-SU-2021:3550-1
SUSE-SU-2021:3553-1
SUSE-SU-2021:3555-1
SUSE-SU-2021:3556-1
SUSE-SU-2021:3557-1
SUSE-SU-2021:3561-1
SUSE-SU-2021:3621-1
SUSE-SU-2021:3906-1
SUSE-SU-2021:3908-1
SUSE-SU-2021_14833-1
SUSE-SU-2021_3550-1
SUSE-SU-2021_3553-1
SUSE-SU-2021_3555-1
SUSE-SU-2021_3556-1
SUSE-SU-2021_3557-1

Affected Products

Alt Linux
Saltstack Salt
Suse