VDB

GSD-2021-25281

GSD-2021-25281 PUBLISHED

An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.

Affected Products

VendorProductVersions
n/an/an/a

Timeline

  • Feb 26, 2021 CVE Published
  • Mar 31, 2021 PoC Published
  • Feb 6, 2025 PoC Published
  • Feb 23, 2025 PoC Published
  • Jan 15, 2026 PoC Published
  • Apr 14, 2026 Distribution Patch
  • Apr 14, 2026 Security Advisory
  • Apr 14, 2026 Security Advisory
  • Apr 14, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›