Vulnerability Description
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Saltstack | Salt | < 2015.8.10 |
| Fedoraproject | Fedora | 32 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://github.com/saltstack/salt/releasesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00009.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-Vendor Advisory
- https://security.gentoo.org/glsa/202103-01Third Party Advisory
- https://security.gentoo.org/glsa/202310-22Third Party Advisory
- https://www.debian.org/security/2021/dsa-5011Third Party Advisory
- https://github.com/saltstack/salt/releasesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00009.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-Vendor Advisory
FAQ
What is CVE-2021-3144?
CVE-2021-3144 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
How severe is CVE-2021-3144?
CVE-2021-3144 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3144?
Check the references section above for vendor advisories and patch information. Affected products include: Saltstack Salt, Fedoraproject Fedora, Debian Debian Linux.