CVE-2021-31607

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).

References

https://sec.stealthcopter.com/saltstack-snapper-minion-privledge-escaltion/

https://lists.fedoraproject.org/archives/list/[email protected]/message/LDKMAJXYFHM4USVX3H5V2GCCBGASWUSM/

https://lists.fedoraproject.org/archives/list/[email protected]/message/MBAHHSGZLEJRCG4DX6J4RBWJAAWH55RQ/

https://lists.fedoraproject.org/archives/list/[email protected]/message/ACVT7M4YLZRLWWQ6SGRK3C6TOF4FXOXT/

https://lists.fedoraproject.org/archives/list/[email protected]/message/6BUWUF5VTENNP2ZYZBVFKPSUHLKLUBD5/

Details

Source: MITRE

Published: 2021-04-23

Updated: 2021-09-25

Type: CWE-77

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* versions from 2016.9 to 3002.6 (inclusive)

Configuration 2

OR

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

Tenable Plugins

View all (9 total)

IDNameProductFamilySeverity
153200Fedora 33 : salt (2021-93a7c8b7c6)NessusFedora Local Security Checks
high
153199Fedora 34 : salt (2021-00ada7e667)NessusFedora Local Security Checks
high
151732openSUSE 15 Security Update : salt (openSUSE-SU-2021:2106-1)NessusSuSE Local Security Checks
critical
151718openSUSE 15 Security Update : salt (openSUSE-SU-2021:1951-1)NessusSuSE Local Security Checks
high
151084SUSE SLES11 Security Update : SUSE Manager Client Tools (SUSE-SU-2021:14753-1)NessusSuSE Local Security Checks
high
151062openSUSE 15 Security Update : salt (openSUSE-SU-2021:0899-1)NessusSuSE Local Security Checks
critical
150920Photon OS 4.0: Salt3 PHSA-2021-4.0-0047NessusPhotonOS Local Security Checks
critical
150743SUSE SLED15 / SLES15 Security Update : salt (SUSE-SU-2021:1951-1)NessusSuSE Local Security Checks
high
149414Fedora 33 : salt (2021-5aaebdae8e)NessusFedora Local Security Checks
high