VDB

CNVD-2021-18372

CNVD-2021-18372 PUBLISHED

SaltStack Salt是SaltStack(Saltstack)公司的一套开源的用于管理基础架构的工具。该工具提供配置管理、远程执行等功能。 SaltStack Salt 3002.5之前版本存在授权问题漏洞,该漏洞源于salt-api未支持eauth凭据,攻击者可利用该漏洞远程运行主机上的任何模块。

Affected Products

VendorProductVersions
n/an/an/a

Timeline

  • Feb 26, 2021 CVE Published
  • Mar 31, 2021 PoC Published
  • Feb 6, 2025 PoC Published
  • Feb 23, 2025 PoC Published
  • Jan 15, 2026 PoC Published
  • Apr 14, 2026 Distribution Patch
  • Apr 14, 2026 Security Advisory
  • Apr 14, 2026 Security Advisory
  • Apr 14, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›