Improper Authentication in Salt - CVE-2021-3144

 

Improper Authentication in Salt - CVE-2021-3144

Published: February 28, 2021


Vulnerability identifier: #VU50986
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3144
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests for expired eauth tokens. A remote attacker can re-use one more time expired eauth tokens to run command against the salt master or minions.


Affected software

Salt
Gentoo Linux
Arch Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Manager Debian
SUSE Linux Enterprise Server
SUSE Manager Tools
SUSE Linux Enterprise Module for Advanced Systems Management
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Manager Ubuntu
Fedora
SUSE Manager
salt (Debian package)
spacecmd
py26-compat-salt
salt-minion
salt-doc
salt
salt-common
salt-zsh-completion
salt-fish-completion
salt-bash-completion
salt-syndic
salt-standalone-formulas-configuration
salt-proxy
salt-ssh
salt-master
salt-cloud
salt-api
python3-salt
python2-salt
app-admin/salt

How to mitigate CVE-2021-3144

Install updates from vendor's website.

Salt - addressed in versions 3000.8, 3001.6, 3002.5
salt (Debian package) - addressed in versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1
spacecmd - addressed in versions 4.2.8-2.15.1, 4.2.8-2.18.1, 4.2.8-2.24.1
py26-compat-salt - addressed in versions 2016.11.10-6.8.1, 2016.11.10-10.22.1
salt-minion - addressed in versions 2016.11.10-43.69.1, 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1, 3002.2-8.41.1
salt-doc - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt - addressed in versions 2016.11.10-43.69.1, 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-common - addressed in versions 3000+ds-1+2.9.1, 3000+ds-1+2.12.1, 3000+ds-1+9.26.1, 3000+ds-1+73.2, 3000+ds-1+74.1, 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1
salt-zsh-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-fish-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3002.2-8.41.1
salt-bash-completion - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-syndic - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-standalone-formulas-configuration - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-proxy - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-ssh - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-master - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-cloud - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
salt-api - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python3-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1, 3002.2-8.41.1
python2-salt - addressed in versions 3000-5.106.1, 3000-24.1, 3000-46.129.1
salt - addressed in versions 3001.6-1.fc32, 3002.5-1.fc33, 3002.5-1.fc34
app-admin/salt - update to 3004.2

External References

Related Security Bulletins