Vulnerability Description
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Saltstack | Salt | <= 3003 |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=1208473
- https://github.com/saltstack/salt/blob/master/salt/modules/status.pyExploitVendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1208473
- https://github.com/saltstack/salt/blob/master/salt/modules/status.pyExploitVendor Advisory
FAQ
What is CVE-2021-33226?
CVE-2021-33226 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third partie...
How severe is CVE-2021-33226?
CVE-2021-33226 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-33226?
Check the references section above for vendor advisories and patch information. Affected products include: Saltstack Salt.