bugzilla.suse.com
https://bugzilla.suse.com/show_bug.cgi?id=1182382 CVE-2021-25315
CRITICAL
salt-api unauthenticated remote code execution
Record summary
CVE-2021-25315 has a selected CVSS score of 9.8 (critical).
Description
CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions.
Description source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
SUSE Linux Enterprise Server 15 SP 3Browse SUSE / SUSE Linux Enterprise Server 15 SP 3 | CVE List | salt to < 3002.2-3 | affected |
TumbleweedBrowse openSUSE / Tumbleweed | CVE List | salt to ≤ 3002.2-2.1 | affected |
| GitHub Advisory | Before 3002.2 · Fixed in 3002.2 | affected |
References
4github.com
https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2021-891.yaml github.com
https://github.com/saltstack/salt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25315