- Description
- An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Data from CISA
- Vulnerability name
- SaltStack Salt Shell Injection Vulnerability
- Exploit added on
- Nov 3, 2021
- Exploit action due
- May 3, 2022
- Required action
- Apply updates per vendor instructions.
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F9405E3-F2B0-41BA-A39D-61BB38475A59",
"versionEndExcluding": "2015.8.10"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A35C23D3-82D4-46E7-BF08-9229C04C0C3D",
"versionEndExcluding": "2015.8.13",
"versionStartIncluding": "2015.8.11"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4741BD5-4C40-48BC-A2C1-E6AB33818201",
"versionEndExcluding": "2016.3.4",
"versionStartIncluding": "2016.3.0"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D28A2B5-316A-45DC-AC85-A0F743C4B3C4",
"versionEndExcluding": "2016.3.6",
"versionStartIncluding": "2016.3.5"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17C96153-85C1-45DC-A48B-46A3900246E2",
"versionEndExcluding": "2016.3.8",
"versionStartIncluding": "2016.3.7"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0A54497-D7E2-4A2C-9719-4D992B296498",
"versionEndExcluding": "2016.11.3",
"versionStartIncluding": "2016.11.0"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "920C57AF-6E88-465A-83FA-AB947D4C6F0B",
"versionEndExcluding": "2016.11.6",
"versionStartIncluding": "2016.11.4"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "11D84847-0C8A-473A-9186-46FABD7BB59A",
"versionEndExcluding": "2016.11.10",
"versionStartIncluding": "2016.11.7"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C45ACC11-CA9B-4451-B6DD-BD784349CDE8",
"versionEndExcluding": "2017.7.4",
"versionStartIncluding": "2017.5.0"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD998745-FA62-4894-A4FC-767F0DE131B9",
"versionEndExcluding": "2017.7.8",
"versionStartIncluding": "2017.7.5"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9747884A-8B29-42C9-BF5E-5B6D883A78E3",
"versionEndExcluding": "2018.3.5",
"versionStartIncluding": "2018.2.0"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7A2912C-7F48-465D-B7F2-93ECD0D0CB74",
"versionEndExcluding": "2019.2.5",
"versionStartIncluding": "2019.2.0"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D64191C4-C3D3-4615-B7D5-26ADA8BD7C7B",
"versionEndExcluding": "3000.3",
"versionStartIncluding": "3000.0"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:3001:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74CAD70E-E77C-4010-B224-CEE3968CB6A2"
},
{
"criteria": "cpe:2.3:a:saltstack:salt:3002:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5D7215A-820E-446C-844C-DC4C61BD1884"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80F0FA5D-8D3B-4C0E-81E2-87998286AF33"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B620311B-34A3-48A6-82DF-6F078D7A4493"
}
],
"operator": "OR"
}
]
}
]