CVE-2021-3144: Critical severity SaltStack Salt vulnerability
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/saltto a version that resolves this vulnerability.Fixed in 2018.3.4+dfsg1-6+deb10u3Fixed in 3002.6+dfsg1-4+deb11u1Fixed in 3004.1+dfsg-2.2 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2019.2.8 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3002.3 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3001.5 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3000.7 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2017.7.8 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.10 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.5 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2015.8.13 - Upgrade
Upgrade
SaltStackto a version that resolves this vulnerability.Fixed in 3002.2Fixed in 3001.4Fixed in 3000.6Fixed in 2019.2.8Fixed in 2019.2.5Fixed in 2018.3.5Fixed in 2017.7.8Fixed in 2016.11.10Fixed in 2016.11.6Fixed in 2016.11.5Fixed in 2016.11.3Fixed in 2016.3.8Fixed in 2016.3.6Fixed in 2016.3.4Fixed in 2015.8.13Fixed in 2015.8.10Fixed in 3002.5Fixed in 3001.6Fixed in 3000.8Fixed in 3002.5Fixed in 3001.6Fixed in 3000.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this SaltStack vulnerability?
The vulnerability ID for this SaltStack vulnerability is CVE-2021-3144.
What is the severity of CVE-2021-3144?
The severity of CVE-2021-3144 is critical.
What is the affected software for CVE-2021-3144?
The affected software for CVE-2021-3144 is SaltStack Salt before 3002.5.
How can this vulnerability be exploited?
This vulnerability can be exploited by using eauth tokens that can be used once after expiration to run commands against the salt master or minions.
Is there a fix available for CVE-2021-3144?
Yes, a fix for CVE-2021-3144 is available. It is recommended to update to version 3002.5 or later of SaltStack Salt.