CVE-2021-25281
Gentoo Linux Security Advisory 202310-22
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
Se detectó un problema por medio de SaltStack Salt versiones anteriores a 3002.5. salt-api no respeta las credenciales de eauth para el cliente wheel_async. Por lo tanto, un atacante puede ejecutar remotamente cualquier módulo wheel en el maestro
It was discovered that Salt incorrectly handled crafted web requests. A remote attacker could possibly use this issue to run arbitrary commands. It was discovered that Salt incorrectly created certificates with weak file permissions. It was discovered that Salt incorrectly handled credential validation. A remote attacker could possibly use this issue to bypass authentication.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2021-01-16 CVE Reserved
- 2021-02-26 First Exploit
- 2021-02-27 CVE Published
- 2024-11-19 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (14)
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | < 2015.8.10 Search vendor "Saltstack" for product "Salt" and version " < 2015.8.10" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2015.8.11 < 2015.8.13 Search vendor "Saltstack" for product "Salt" and version " >= 2015.8.11 < 2015.8.13" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2016.3.0 < 2016.3.4 Search vendor "Saltstack" for product "Salt" and version " >= 2016.3.0 < 2016.3.4" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2016.3.5 < 2016.3.6 Search vendor "Saltstack" for product "Salt" and version " >= 2016.3.5 < 2016.3.6" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2016.3.7 < 2016.3.8 Search vendor "Saltstack" for product "Salt" and version " >= 2016.3.7 < 2016.3.8" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2016.3.9 < 2016.11.3 Search vendor "Saltstack" for product "Salt" and version " >= 2016.3.9 < 2016.11.3" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2016.11.4 < 2016.11.5 Search vendor "Saltstack" for product "Salt" and version " >= 2016.11.4 < 2016.11.5" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2016.11.7 < 2016.11.10 Search vendor "Saltstack" for product "Salt" and version " >= 2016.11.7 < 2016.11.10" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2017.5.0 < 2017.7.8 Search vendor "Saltstack" for product "Salt" and version " >= 2017.5.0 < 2017.7.8" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2018.2.0 <= 2018.3.5 Search vendor "Saltstack" for product "Salt" and version " >= 2018.2.0 <= 2018.3.5" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2019.2.0 < 2019.2.5 Search vendor "Saltstack" for product "Salt" and version " >= 2019.2.0 < 2019.2.5" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 2019.2.6 < 2019.2.8 Search vendor "Saltstack" for product "Salt" and version " >= 2019.2.6 < 2019.2.8" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 3000 < 3000.6 Search vendor "Saltstack" for product "Salt" and version " >= 3000 < 3000.6" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 3001 < 3001.4 Search vendor "Saltstack" for product "Salt" and version " >= 3001 < 3001.4" | - |
Affected
| ||||||
Saltstack Search vendor "Saltstack" | Salt Search vendor "Saltstack" for product "Salt" | >= 3002 < 3002.5 Search vendor "Saltstack" for product "Salt" and version " >= 3002 < 3002.5" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 32 Search vendor "Fedoraproject" for product "Fedora" and version "32" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
|