cbcvebase.
CVE-2021-3148
published 2021-02-27

CVE-2021-3148: An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.25%
94.2th percentile
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
saltstacksalt< 2015.8.102015.8.10
saltstacksalt>= 0 < 2015.8.102015.8.10
saltstacksalt>= 0 < 2015.8.132015.8.13
saltstacksalt>= 0 < 2015.8.8+ds-1ubuntu0.1+esm22015.8.8+ds-1ubuntu0.1+esm2
saltstacksalt>= 0 < 2017.7.4+dfsg1-1ubuntu18.04.2+esm12017.7.4+dfsg1-1ubuntu18.04.2+esm1
saltstacksalt>= 2015.8.11 < 2015.8.132015.8.13
saltstacksalt>= 2015.8.11 < 2015.8.132015.8.13
saltstacksalt>= 2016.11.0 < 2016.11.32016.11.3
saltstacksalt>= 2016.11.4 < 2016.11.52016.11.5
saltstacksalt>= 2016.11.4 < 2016.11.52016.11.5
saltstacksalt>= 2016.11.7 < 2016.11.102016.11.10
saltstacksalt>= 2016.11.7 < 2016.11.102016.11.10
saltstacksalt>= 2016.3.0 < 2016.3.42016.3.4
saltstacksalt>= 2016.3.0 < 2016.3.42016.3.4
saltstacksalt>= 2016.3.0 < 2016.11.52016.11.5
saltstacksalt>= 2016.3.5 < 2016.3.62016.3.6
saltstacksalt>= 2016.3.5 < 2016.3.62016.3.6
saltstacksalt>= 2016.3.7 < 2016.3.82016.3.8
saltstacksalt>= 2016.3.7 < 2016.3.82016.3.8

Detection & IOCsextracted from sources · hover to see the quote

  • Command injection via crafted web requests to the Salt API targeting salt.utils.thin.gen_thin(), exploiting json.dumps() escaping double quotes while leaving single quotes untouched
  • Monitor Salt API HTTP requests for payloads containing unescaped single quotes, which may indicate exploitation of the quote-handling discrepancy in salt/utils/thin.py
  • Focus detection on the file salt/utils/thin.py and the gen_thin() function for anomalous subprocess or shell execution activity
  • ·Vulnerability affects SaltStack Salt versions before 3002.5; ensure patched versions are not flagged as vulnerable
  • ·Red Hat Ceph Storage 2 package 'salt' is out of support scope and will not receive a patch from Red Hat

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.