CVE-2021-3197: Critical severity SaltStack Salt vulnerability
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via sshoptions provided in an API request.
Other sources
The Salt-API’s SSH client is vulnerable to a shell injection by including ProxyCommand in an argument, or via sshoptions provided in an API request.
— Salt Project
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3002.3 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3001.5 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3000.7 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2019.2.8 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2017.7.8 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.10 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.5 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2015.8.13 - Upgrade
Upgrade
SaltStackto a version that resolves this vulnerability.Fixed in 3002.2Fixed in 3001.4Fixed in 3000.6Fixed in 2019.2.8Fixed in 2019.2.5Fixed in 2018.3.5Fixed in 2017.7.8Fixed in 2016.11.10Fixed in 2016.11.6Fixed in 2016.11.5Fixed in 2016.11.3Fixed in 2016.3.8Fixed in 2016.3.6Fixed in 2016.3.4Fixed in 2015.8.13Fixed in 2015.8.10Fixed in 3002.5Fixed in 3001.6Fixed in 3000.8Fixed in 3002.5Fixed in 3001.6Fixed in 3000.8 - Compensating control
Avoid accepting untrusted input for Salt-API ssh client parameters: do not allow ProxyCommand to be passed in an argument or via ssh_options in API requests.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3197?
CVE-2021-3197 is a vulnerability in SaltStack Salt before version 3002.5.
How severe is CVE-2021-3197?
CVE-2021-3197 has a severity score of 9.8 (critical).
Which software is affected by CVE-2021-3197?
SaltStack Salt versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1, and 3004.1+dfsg-2.2 are affected by CVE-2021-3197.
How can I fix CVE-2021-3197?
To fix CVE-2021-3197, update SaltStack Salt to version 3002.5 or later.
Where can I find more information about CVE-2021-3197?
More information about CVE-2021-3197 can be found in the following references: [1] [2] [3].