Command Injection in Salt - CVE-2021-3148

 

Command Injection in Salt - CVE-2021-3148

Published: February 28, 2021


Vulnerability identifier: #VU50984
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3148
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands within the application.

The vulnerability exists due to improper input validation, related to handling single and double quotes, within the salt.utils.thin.gen_thin() function in salt/utils/thin.py. A remote user can send a specially crafted HTTP request to the SaltAPI and execute arbitrary commands.


Affected software

Salt
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Manager Debian
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Advanced Systems Management
SUSE Manager Tools
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Manager Ubuntu
Ubuntu
Fedora
SUSE Manager
salt (Debian package)
salt-common (Ubuntu package)
spacecmd
py26-compat-salt
salt-minion
salt-doc
salt
salt-common
salt-zsh-completion
salt-fish-completion
salt-bash-completion
salt-syndic
salt-standalone-formulas-configuration
salt-proxy
salt-ssh
salt-master
salt-cloud
salt-api
python3-salt
python2-salt
app-admin/salt

How to mitigate CVE-2021-3148

Install updates from vendor's website.

Salt - addressed in versions 3000.8, 3001.6, 3002.5
salt (Debian package) - addressed in versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1
salt-common (Ubuntu package) - update to Ubuntu Pro
spacecmd - addressed in versions 4.2.8-2.15.1, 4.2.8-2.18.1, 4.2.8-2.24.1
py26-compat-salt - addressed in versions 2016.11.10-6.8.1, 2016.11.10-10.22.1
salt-minion - addressed in versions 2016.11.10-43.69.1, 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1, 3002.2-8.41.1
salt-doc - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-common - addressed in versions 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1
salt-zsh-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-fish-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3002.2-8.41.1
salt-bash-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-syndic - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-standalone-formulas-configuration - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-proxy - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-ssh - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-master - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-cloud - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-api - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python3-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python2-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1
salt - addressed in versions 3001.6-1.fc32, 3002.5-1.fc33, 3002.5-1.fc34
app-admin/salt - update to 3004.2

External References

Related Security Bulletins