CVE-2021-3197 PUBLISHED

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.

EPSS 9.93% · 93.0th percentile

Risk Scores

EPSS Score
9.93%
93.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSsalt0, *, 2017.7.4+dfsg1-1ubuntu18.04.1
Ubuntu:Pro:14.04:LTSsalt0.17.4-2, 0.17.5+ds-1, 0.17.5+ds-1ubuntu0.1~esm1
Ubuntu:22.04:LTSsalt*, 0, 3002.7+dfsg1-1
Ubuntu:Pro:16.04:LTSsalt2015.8.3+ds-2, 2015.8.3+ds-1, 2015.8.1+ds-2

Timeline

References

Open in Interactive Console →