CVE-2021-3144

Severity
9.1CRITICAL
EPSS
4.7%
top 10.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateMay 24

Description

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

NVDsaltstack/salt2015.8.112015.8.13+14
PyPIsalt2016.3.02016.11.5+22

Also affects: Debian Linux 10.0, 11.0, 9.0, Fedora 32, 33, 34

🔴Vulnerability Details

4
OSV
SaltStack Salt eauth tokens can be used once after expiration2022-05-24
GHSA
SaltStack Salt eauth tokens can be used once after expiration2022-05-24
OSV
CVE-2021-3144: In SaltStack Salt before 30022021-02-27
CVEList
CVE-2021-3144: In SaltStack Salt before 30022021-02-27

📋Vendor Advisories

1
Red Hat
salt: eauth tokens can be used once after expiration2021-02-25