CVE-2021-21996: High severity saltstack vulnerability
A user who has control of the source, and sourcehash URLs can gain full file system access as root on a salt minion.
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-21996?
CVE-2021-21996 is a vulnerability in SaltStack Salt before version 3003.3 that allows a user to gain full file system access as root on a salt minion.
What is the severity of CVE-2021-21996?
The severity of CVE-2021-21996 is high with a CVSS score of 7.5.
How does CVE-2021-21996 affect SaltStack Salt?
CVE-2021-21996 affects SaltStack Salt versions before 3003.3.
How can I fix CVE-2021-21996?
To fix CVE-2021-21996, update SaltStack Salt to version 3003.3 or later.
Where can I find more information about CVE-2021-21996?
You can find more information about CVE-2021-21996 at the following references: [1](https://security-tracker.debian.org/tracker/CVE-2021-21996), [2](https://security-tracker.debian.org/tracker/CVE-2021-22004), [3](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21996)