CVE-2021-3144

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/02/2021
Last modified:
21/12/2023

Description

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2015.8.10 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2015.8.11 (including) 2015.8.13 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2016.3.0 (including) 2016.3.4 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2016.3.5 (including) 2016.3.6 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2016.3.7 (including) 2016.3.8 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2016.3.9 (including) 2016.11.3 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2016.11.4 (including) 2016.11.5 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2016.11.7 (including) 2016.11.10 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2017.5.0 (including) 2017.7.8 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2018.2.0 (including) 2018.3.5 (including)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2019.2.0 (including) 2019.2.5 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 2019.2.6 (including) 2019.2.8 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 3000 (including) 3000.6 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 3001 (including) 3001.4 (excluding)
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* 3002 (including) 3002.5 (excluding)