CVE-2021-3148: Command Injection
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.genthin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.
Other sources
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.genthin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.
command injection in salt.utils.thin.genthin()
— Salt Project
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3002.3 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3001.5 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3000.7 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2019.2.8 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2017.7.8 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.10 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.5 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2015.8.13 - Upgrade
Upgrade
SaltStackto a version that resolves this vulnerability.Fixed in 3002.2Fixed in 3001.4Fixed in 3000.6Fixed in 2019.2.8Fixed in 2019.2.5Fixed in 2018.3.5Fixed in 2017.7.8Fixed in 2016.11.10Fixed in 2016.11.6Fixed in 2016.11.5Fixed in 2016.11.3Fixed in 2016.3.8Fixed in 2016.3.6Fixed in 2016.3.4Fixed in 2015.8.13Fixed in 2015.8.10Fixed in 3002.5Fixed in 3001.6Fixed in 3000.8Fixed in 3002.5Fixed in 3001.6Fixed in 3000.8 - Upgrade
Upgrade
SaltStack Saltto a version that resolves this vulnerability.Fixed in 3002.5
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3148?
CVE-2021-3148 is a vulnerability in SaltStack Salt before version 3002.5, which allows for command injection through crafted web requests to the Salt API.
How severe is CVE-2021-3148?
CVE-2021-3148 has a severity rating of 9.8 (critical).
What is the affected software for CVE-2021-3148?
The affected software for CVE-2021-3148 includes SaltStack Salt versions before 3002.5.
How can I fix CVE-2021-3148?
To fix CVE-2021-3148, you should update to SaltStack Salt version 3002.5 or later.
Where can I find more information about CVE-2021-3148?
You can find more information about CVE-2021-3148 in the release notes of SaltStack Salt and the advisory links provided.