CVE-2021-25283: Code Injection
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
Other sources
The jinja renderer does not protect against server-side template injection attacks.
— Salt Project
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-25283?
CVE-2021-25283 is a vulnerability in SaltStack Salt before version 3002.5 that allows server-side template injection attacks.
How severe is CVE-2021-25283?
CVE-2021-25283 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2021-25283?
SaltStack Salt versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1, and 3004.1+dfsg-2.2 are affected by CVE-2021-25283.
How can I fix CVE-2021-25283?
To fix CVE-2021-25283, update SaltStack Salt to version 3002.5 or later.
Where can I find more information about CVE-2021-25283?
You can find more information about CVE-2021-25283 at the following references: [Link 1](https://github.com/saltstack/salt/releases), [Link 2](https://lists.debian.org/debian-lts-announce/2021/11/msg00009.html), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVB/).