CVE-2021-25283

CRITICAL

SaltStack Salt <3002.5 - Code Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.

Scores

CVSS v3 9.8
EPSS 0.1043
EPSS Percentile 95.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (8)
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 32
fedoraproject/fedora 33
fedoraproject/fedora 34
pypi/salt 0 - 2015.8.13PyPI
saltstack/salt < 2015.8.10
Published Feb 27, 2021
Tracked Since Feb 18, 2026