CVE-2021-25281
27.02.2021, 05:15
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.Enginsight
Vendor | Product | Version |
---|---|---|
saltstack | salt | 𝑥 < 2015.8.10 |
saltstack | salt | 2015.8.11 ≤ 𝑥 < 2015.8.13 |
saltstack | salt | 2016.3.0 ≤ 𝑥 < 2016.3.4 |
saltstack | salt | 2016.3.5 ≤ 𝑥 < 2016.3.6 |
saltstack | salt | 2016.3.7 ≤ 𝑥 < 2016.3.8 |
saltstack | salt | 2016.3.9 ≤ 𝑥 < 2016.11.3 |
saltstack | salt | 2016.11.4 ≤ 𝑥 < 2016.11.5 |
saltstack | salt | 2016.11.7 ≤ 𝑥 < 2016.11.10 |
saltstack | salt | 2017.5.0 ≤ 𝑥 < 2017.7.8 |
saltstack | salt | 2018.2.0 ≤ 𝑥 ≤ 2018.3.5 |
saltstack | salt | 2019.2.0 ≤ 𝑥 < 2019.2.5 |
saltstack | salt | 2019.2.6 ≤ 𝑥 < 2019.2.8 |
saltstack | salt | 3000 ≤ 𝑥 < 3000.6 |
saltstack | salt | 3001 ≤ 𝑥 < 3001.4 |
saltstack | salt | 3002 ≤ 𝑥 < 3002.5 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References