CVE-2021-25284: Medium severity saltstack vulnerability
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
Other sources
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
webutils write passwords in cleartext to /var/log/salt/minion
— Salt Project
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-25284?
CVE-2021-25284 is a vulnerability in SaltStack Salt before version 3002.5 that allows the salt.modules.cmdmod module to log credentials to the info or error log level.
What is the severity of CVE-2021-25284?
The severity of CVE-2021-25284 is medium (4.4).
How can I fix CVE-2021-25284?
To fix CVE-2021-25284, update SaltStack Salt to version 3002.5 or later.
Where can I find more information about CVE-2021-25284?
You can find more information about CVE-2021-25284 on the following references: [Reference 1](https://github.com/saltstack/salt/releases), [Reference 2](https://lists.debian.org/debian-lts-announce/2021/11/msg00009.html), [Reference 3](https://lists.debian.org/debian-lts-announce/2022/01/msg00000.html).
What is the CWE of CVE-2021-25284?
The CWE of CVE-2021-25284 is CWE-522 and CWE-532.