VDB

CVE-2021-3144

CVE-2021-3144 PUBLISHED CVSS 9.100000381469727 CRITICAL

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

EPSS 5.24% · 92.0th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
5.24%
92.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSsalt2015.8.3+ds-3, 2015.8.5+ds-1, 2015.8.7+ds-1
Ubuntu:Pro:14.04:LTSsalt0.17.2-3, 0.17.2-2, 0.17.4-1
Ubuntu:Pro:18.04:LTSsalt*, 2016.11.8+dfsg1-1, 2017.7.2+dfsg1-2ubuntu1
Ubuntu:22.04:LTSsalt0, 3002.6+dfsg1-4, 3002.7+dfsg1-1

Timeline

  • Feb 26, 2021 CVE Published
  • Mar 31, 2021 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Jun 18, 2023 EPSS Score
  • Nov 1, 2023 EPSS Score
  • Nov 12, 2023 EPSS Score
  • Apr 30, 2024 EPSS Score
  • Aug 3, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›