Seagate/cortx-prvsnr

CVE-2021-3197 (High) detected in salt-3002.2.tar.gz

Closed this issue · 4 comments

CVE-2021-3197 - High Severity Vulnerability

Vulnerable Library - salt-3002.2.tar.gz

Portable, distributed, remote execution and configuration management system

Library home page: https://files.pythonhosted.org/packages/b5/45/a20ff8a3cad48b50a924ee9c65f2df0e214de4fa282c4feef2e1d6a0b886/salt-3002.2.tar.gz

Path to dependency file: cortx-prvsnr/lr-cli

Path to vulnerable library: /lr-cli,/api/python,/api/python/provisioner/commands/configure

Dependency Hierarchy:

  • salt-3002.2.tar.gz (Vulnerable Library)

Found in HEAD commit: 9b38cd0cecf207c523b9661cdceea8063b6b8293

Vulnerability Details

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.

Publish Date: 2021-02-27

URL: CVE-2021-3197

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/saltstack/salt/blob/master/CHANGELOG.md

Release Date: 2021-02-27

Fix Resolution: v3002.3

stale commented

This issue/pull request has been marked as needs attention as it has been left pending without new activity for 4 days. Tagging @83bhp @andkononykhin2 for appropriate assignment. Sorry for the delay & Thank you for contributing to CORTX. We will get back to you as soon as possible.

Swanand Gadre commented in Jira Server:

Closing this bug as duplicate of 

https://jts.seagate.com/browse/EOS-23827

 

All the Salt package related vulnerability bugs will be tracked thru 

https://jts.seagate.com/browse/EOS-23827

Swanand Gadre commented in Jira Server:

Closing this bug as duplicate of 

https://jts.seagate.com/browse/EOS-23827

 

All the Salt package related vulnerability bugs will be tracked thru 

https://jts.seagate.com/browse/EOS-23827

Swanand Gadre commented in Jira Server:

Closing this bug as duplicate of 

https://jts.seagate.com/browse/EOS-23827

 

All the Salt package related vulnerability bugs will be tracked thru 

https://jts.seagate.com/browse/EOS-23827