Improper access control in Salt - CVE-2021-25281

 

Improper access control in Salt - CVE-2021-25281

Published: February 28, 2021 / Updated: May 9, 2021


Vulnerability identifier: #VU50979
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25281
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. The salt-api does not honor eauth credentials for the wheel_async client. A remote attacker can remotely run any wheel modules on the master.


Affected software

Salt
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Manager Debian
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Advanced Systems Management
SUSE Manager Tools
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Manager Ubuntu
Ubuntu
Fedora
SUSE Manager
salt (Debian package)
salt-common (Ubuntu package)
spacecmd
py26-compat-salt
salt-minion
salt-doc
salt
salt-common
salt-zsh-completion
salt-fish-completion
salt-bash-completion
salt-syndic
salt-standalone-formulas-configuration
salt-proxy
salt-ssh
salt-master
salt-cloud
salt-api
python3-salt
python2-salt
app-admin/salt

How to mitigate CVE-2021-25281

Install updates from vendor's website.

Salt - addressed in versions 3000.8, 3001.6, 3002.5
salt (Debian package) - addressed in versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1
salt-common (Ubuntu package) - update to Ubuntu Pro
spacecmd - addressed in versions 4.2.8-2.15.1, 4.2.8-2.18.1, 4.2.8-2.24.1
py26-compat-salt - addressed in versions 2016.11.10-6.8.1, 2016.11.10-10.22.1
salt-minion - addressed in versions 2016.11.10-43.69.1, 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1, 3002.2-8.41.1
salt-doc - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-common - addressed in versions 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1
salt-zsh-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-fish-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3002.2-8.41.1
salt-bash-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-syndic - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-standalone-formulas-configuration - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-proxy - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-ssh - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-master - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-cloud - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-api - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python3-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python2-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1
salt - addressed in versions 3001.6-1.fc32, 3002.5-1.fc33, 3002.5-1.fc34
app-admin/salt - update to 3004.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins