UBUNTU-CVE-2021-25281
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-25281
UBUNTU-CVE-2021-25281
Summary:
Details: An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
References: https://ubuntu.com/security/CVE-2021-25281, https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/, https://github.com/saltstack/salt/releases, https://www.saltstack.com/blog/active-saltstack-cve-announced-2021-jan-21/, https://www.cve.org/CVERecord?id=CVE-2021-25281, https://ubuntu.com/security/notices/USN-6948-1
Affected packages
Package
Name: salt
Purl: pkg:deb/ubuntu/[email protected]+ds-1ubuntu0.1~esm5?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
