CVE-2021-3148

Description

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
12.138

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in VMware SALT 2016.11.2Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.11.4Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.3.7Windows
Multiple Vulnerabilities are affected in VMware SALT 2015.8.12Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.3.3Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.3.5Windows
Multiple Vulnerabilities are affected in VMware SALT 2017.7.7Windows
Multiple Vulnerabilities are affected in VMware SALT 2015.8.9Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.11.9Windows
Multiple Vulnerabilities are affected in VMware SALT 2019.2.4Windows
Multiple Vulnerabilities are affected in VMware SALT 2018.3.5Windows
Multiple Vulnerabilities are affected in VMware SALT 2019.2.7Windows
Multiple Vulnerabilities are affected in VMware SALT 3000.5Windows
Multiple Vulnerabilities are affected in VMware SALT 3001.3Windows
Multiple Vulnerabilities are affected in VMware SALT 3002.4Windows
Multiple vulnerabilities are fixed in Python-salt 2015.8.13Windows
Multiple vulnerabilities are fixed in Python-salt 2016.11.10Windows
Multiple vulnerabilities are fixed in Python-salt 2017.7.8Windows
Multiple vulnerabilities are fixed in Python-salt 2016.11.5Windows
Multiple vulnerabilities are fixed in Python-salt 2019.2.8Windows
Multiple vulnerabilities are fixed in Python-salt 3000.7Windows
Multiple vulnerabilities are fixed in Python-salt 3001.5Windows
Multiple vulnerabilities are fixed in Python-salt 3002.3Windows
Multiple vulnerabilities are affected in Python-salt 2018.3.5Windows
Multiple vulnerabilities are fixed in Python-salt for linux 2015.8.13Linux
Multiple vulnerabilities are fixed in Python-salt for linux 2016.11.10Linux
Multiple vulnerabilities are fixed in Python-salt for linux 2017.7.8Linux
Multiple vulnerabilities are fixed in Python-salt for linux 2016.11.5Linux
Multiple vulnerabilities are fixed in Python-salt for linux 2019.2.8Linux
Multiple vulnerabilities are fixed in Python-salt for linux 3000.7Linux
Multiple vulnerabilities are fixed in Python-salt for linux 3001.5Linux
Multiple vulnerabilities are fixed in Python-salt for linux 3002.3Linux
Multiple vulnerabilities are affected in Python-salt for linux 2018.3.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234