Back to search
CVE-2021-31607
Published: Apr 23, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2021-5aaebdae8e
vendor-advisory
FEDORA-2021-00ada7e667
vendor-advisory
FEDORA-2021-93a7c8b7c6
vendor-advisory
FEDORA-2021-158e9c6eb9
vendor-advisory
DSA-5011
vendor-advisory
GLSA-202310-22
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now