VDB
CVE-2021-3144
CVE-2021-3144
PUBLISHED
CVSS 9.100000381469727 CRITICAL
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
EPSS 5.24% · 92.0th percentile
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
5.24%
92.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | salt | 2015.8.3+ds-3, 2015.8.5+ds-1, 2015.8.7+ds-1 |
| Ubuntu:Pro:14.04:LTS | salt | 0.17.2-3, 0.17.2-2, 0.17.4-1 |
| Ubuntu:Pro:18.04:LTS | salt | *, 2016.11.8+dfsg1-1, 2017.7.2+dfsg1-2ubuntu1 |
| Ubuntu:22.04:LTS | salt | 0, 3002.6+dfsg1-4, 3002.7+dfsg1-1 |
Timeline
- Feb 26, 2021 CVE Published
- Mar 31, 2021 PoC Published
- Apr 14, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Jun 18, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
- Nov 12, 2023 EPSS Score
- Apr 30, 2024 EPSS Score
- Aug 3, 2024 CVE Updated
References
- https://ubuntu.com/security/CVE-2021-3144 third-party-advisory
- https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/ third-party-advisory
- https://github.com/saltstack/salt/releases third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3144 third-party-advisory