CVE-2021-3197 (High) detected in salt-3002.2.tar.gz
Closed this issue · 4 comments
CVE-2021-3197 - High Severity Vulnerability
Vulnerable Library - salt-3002.2.tar.gz
Portable, distributed, remote execution and configuration management system
Library home page: https://files.pythonhosted.org/packages/b5/45/a20ff8a3cad48b50a924ee9c65f2df0e214de4fa282c4feef2e1d6a0b886/salt-3002.2.tar.gz
Path to dependency file: cortx-prvsnr/lr-cli
Path to vulnerable library: /lr-cli,/api/python,/api/python/provisioner/commands/configure
Dependency Hierarchy:
- ❌ salt-3002.2.tar.gz (Vulnerable Library)
Found in HEAD commit: 9b38cd0cecf207c523b9661cdceea8063b6b8293
Vulnerability Details
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
Publish Date: 2021-02-27
URL: CVE-2021-3197
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: https://github.com/saltstack/salt/blob/master/CHANGELOG.md
Release Date: 2021-02-27
Fix Resolution: v3002.3
This issue/pull request has been marked as needs attention
as it has been left pending without new activity for 4 days. Tagging @83bhp @andkononykhin2 for appropriate assignment. Sorry for the delay & Thank you for contributing to CORTX. We will get back to you as soon as possible.
Swanand Gadre commented in Jira Server:
Closing this bug as duplicate of
https://jts.seagate.com/browse/EOS-23827
All the Salt package related vulnerability bugs will be tracked thru
Swanand Gadre commented in Jira Server:
Closing this bug as duplicate of
https://jts.seagate.com/browse/EOS-23827
All the Salt package related vulnerability bugs will be tracked thru
Swanand Gadre commented in Jira Server:
Closing this bug as duplicate of
https://jts.seagate.com/browse/EOS-23827
All the Salt package related vulnerability bugs will be tracked thru