CVE-2021-25282: Path Traversal
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillarroots.write method is vulnerable to directory traversal.
Other sources
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillarroots.write method is vulnerable to directory traversal.
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-25282?
CVE-2021-25282 is an issue discovered in SaltStack Salt before 3002.5, where the salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
What is the severity of CVE-2021-25282?
The severity of CVE-2021-25282 is critical with a CVSS score of 9.1.
Which software versions are affected by CVE-2021-25282?
The affected software versions include SaltStack Salt 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1, and 3004.1+dfsg-2.2.
How can I fix CVE-2021-25282?
To fix CVE-2021-25282, it is recommended to upgrade to SaltStack Salt version 3002.5 or higher.
Where can I find more information about CVE-2021-25282?
More information about CVE-2021-25282 can be found at the following references: http://packetstormsecurity.com/files/162058/SaltStack-Salt-API-Unauthenticated-Remote-Command-Execution.html, https://github.com/saltstack/salt/releases, and https://lists.debian.org/debian-lts-announce/2021/11/msg00009.html.