← Back

CVE-2021-3144

nvd nist
Published: Feb 27, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

Affected (21)

1 product
Salt
1 product
Fedora
1 product
Debian Linux
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Saltstack
Before 2015.8.10
From 2015.8.11 to 2015.8.13
From 2016.11.4 to 2016.11.5
From 2016.11.7 to 2016.11.10
From 2016.3.0 to 2016.3.4
From 2016.3.5 to 2016.3.6
From 2016.3.7 to 2016.3.8
From 2016.3.9 to 2016.11.3
From 2017.5.0 to 2017.7.8
From 2018.2.0 to 2018.3.5
From 2019.2.0 to 2019.2.5
From 2019.2.6 to 2019.2.8
From 3000 to 3000.6
From 3001 to 3001.4
From 3002 to 3002.5
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Version 34
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 9.0

References (18)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.