Vulnerability Name:

CVE-2021-21996 (CCN-209043)

Assigned:2021-09-02
Published:2021-09-02
Updated:2022-07-12
Summary:An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2021-21996

Source: XF
Type: UNKNOWN
saltstack-cve202121996-priv-esc(209043)

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20211119 [SECURITY] [DLA 2823-1] salt security update

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20211121 [SECURITY] [DLA 2823-2] salt regression update

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-158e9c6eb9

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-93a7c8b7c6

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-00ada7e667

Source: CCN
Type: Salt Security Advisory 2021-SEP-02
Salt Security Advisory Release

Source: MISC
Type: Patch, Vendor Advisory
https://saltproject.io/security_announcements/salt-security-advisory-2021-sep-02/

Source: DEBIAN
Type: Third Party Advisory
DSA-5011

Vulnerable Configuration:Configuration 1:
  • cpe:/a:saltstack:salt:*:*:*:*:*:*:*:* (Version < 3000.3)

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:35:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:11.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7998
    P
    cblas-devel-3.9.0-150000.4.13.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:8092
    P
    salt-transactional-update-3005.1-150500.2.13 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:8064
    P
    sccache-0.3.0~git5.14a4b8b-150300.7.9.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:8081
    P
    libcgroup-devel-0.41.rc1-1.10.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7784
    P
    python3-salt-3005.1-150500.2.13 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8079
    P
    java-1_8_0-ibm-1.8.0_sr8.0-150000.3.71.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:801
    P
    Security update for cifs-utils (Moderate)
    2022-10-05
    oval:org.opensuse.security:def:3522
    P
    hardlink-1.0-6.38 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3537
    P
    kdump-0.8.16-9.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3518
    P
    guile-2.0.9-9.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3702
    P
    libvte9-0.28.2-19.7 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3181
    P
    libgssglue1-0.4-3.76 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94811
    P
    python3-salt-3004-150400.6.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94630
    P
    libcontainers-common-20210626-150400.1.3 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95152
    P
    salt-api-3004-150400.6.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95167
    P
    salt-transactional-update-3004-150400.6.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:99756
    P
    (Important)
    2022-03-04
    oval:org.opensuse.security:def:100067
    P
    (Important)
    2022-01-25
    oval:org.opensuse.security:def:113236
    P
    python3-salt-3002.2-6.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:99163
    P
    (Important)
    2021-12-01
    oval:org.opensuse.security:def:95986
    P
    Security update for SUSE Manager Server 4.1 (Moderate)
    2021-11-05
    oval:org.opensuse.security:def:111122
    P
    Security update for salt (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:96079
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:38441
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:92018
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:42234
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:106247
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:69168
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:42859
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:99156
    P
    (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:9415
    P
    Security update for Salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:99358
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:92806
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:117523
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:109435
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:69947
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:105658
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:64791
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:100675
    P
    (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:10358
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:101343
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:8668
    P
    Security update for Salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:96108
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:20610
    P
    Security update for Salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:92213
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:106446
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:69170
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:1641
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:42874
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:99691
    P
    (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:9608
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:99557
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:118531
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:109464
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:70309
    P
    Security update for Salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:105853
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:69087
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:102217
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:73729
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:102769
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:8857
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:98968
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:92408
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:106733
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:69555
    P
    Security update for Salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:1700
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:111768
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:49081
    P
    Security update for Salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:100010
    P
    (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:9807
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:118560
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:38426
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:70498
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:42136
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:106048
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:69153
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:102261
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:73913
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:102798
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:9052
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:92607
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:108009
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:69748
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:64607
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:100346
    P
    (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:10169
    P
    Security update for Salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:106653
    P
    python3-salt-3002.2-6.1 on GA media (Moderate)
    2021-10-01
    BACK
    saltstack salt *
    fedoraproject fedora 33
    fedoraproject fedora 34
    fedoraproject fedora 35
    debian debian linux 9.0
    debian debian linux 10.0
    debian debian linux 11.0