OS Command Injection in Salt - CVE-2021-3197

 

OS Command Injection in Salt - CVE-2021-3197

Published: February 28, 2021


Vulnerability identifier: #VU50981
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3197
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation within the salt-api ssh client. A remote attacker can include the ProxyCommand in an argument, or via ssh_options provided in an API request and execute arbitrary commands on the system.



Affected software

Salt
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Manager Debian
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Advanced Systems Management
SUSE Manager Tools
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Manager Ubuntu
Ubuntu
Fedora
SUSE Manager
salt (Debian package)
salt-common (Ubuntu package)
spacecmd
py26-compat-salt
salt-minion
salt-doc
salt
salt-common
salt-zsh-completion
salt-fish-completion
salt-bash-completion
salt-syndic
salt-standalone-formulas-configuration
salt-proxy
salt-ssh
salt-master
salt-cloud
salt-api
python3-salt
python2-salt
app-admin/salt

How to mitigate CVE-2021-3197

Install updates from vendor's website.

Salt - addressed in versions 3000.8, 3001.6, 3002.5
salt (Debian package) - addressed in versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1
salt-common (Ubuntu package) - update to Ubuntu Pro
spacecmd - addressed in versions 4.2.8-2.15.1, 4.2.8-2.18.1, 4.2.8-2.24.1
py26-compat-salt - addressed in versions 2016.11.10-6.8.1, 2016.11.10-10.22.1
salt-minion - addressed in versions 2016.11.10-43.69.1, 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1, 3002.2-8.41.1
salt-doc - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-common - addressed in versions 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1
salt-zsh-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-fish-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3002.2-8.41.1
salt-bash-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-syndic - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-standalone-formulas-configuration - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-proxy - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-ssh - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-master - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-cloud - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-api - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python3-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python2-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1
salt - addressed in versions 3001.6-1.fc32, 3002.5-1.fc33, 3002.5-1.fc34
app-admin/salt - update to 3004.2

External References

Related Security Bulletins