Back to search
CVE-2021-3148
Published: Feb 27, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2021-904a2dbc0c
vendor-advisory
FEDORA-2021-5756fbf8a6
vendor-advisory
FEDORA-2021-43eb5584ad
vendor-advisory
GLSA-202103-01
vendor-advisory
DSA-5011
vendor-advisory
GLSA-202310-22
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now