CVE-2021-25315: salt-api unauthenticated remote code execution
A Incorrect Implementation of Authentication Algorithm vulnerability in of SUSE SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions.
Other sources
CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25315?
CVE-2021-25315 is a vulnerability in SUSE Linux Enterprise Server 15 SP 3 and openSUSE Tumbleweed that allows local attackers to execute arbitrary code via salt without the need for valid credentials.
What is the severity of CVE-2021-25315?
The severity of CVE-2021-25315 is critical, with a severity value of 7.8.
Which software versions are affected by CVE-2021-25315?
The affected software versions are SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2 and SaltStack Salt.
How can the vulnerability CVE-2021-25315 be fixed?
To fix CVE-2021-25315, it is recommended to update to salt versions 3002.2 or later.
Where can I find more information about CVE-2021-25315?
More information about CVE-2021-25315 can be found at the following URL: https://bugzilla.suse.com/show_bug.cgi?id=1182382