CVE-2021-25281: Critical severity saltstack vulnerability
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheelasync client. Thus, an attacker can remotely run any wheel modules on the master.
Other sources
The Salt-API does not have eAuth credentials for the wheelasync client
— Salt Project
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-25281?
CVE-2021-25281 is a vulnerability in SaltStack Salt before version 3002.5 that allows remote attackers to run any wheel modules on the master.
What is the severity of CVE-2021-25281?
CVE-2021-25281 has a severity rating of 9.8, which is considered critical.
How does CVE-2021-25281 affect SaltStack Salt?
CVE-2021-25281 affects SaltStack Salt versions before 3002.5.
How can I fix CVE-2021-25281?
To fix CVE-2021-25281, you should upgrade SaltStack Salt to version 3002.5 or later.
Where can I find more information about CVE-2021-25281?
You can find more information about CVE-2021-25281 at the following references: [1] [2] [3].