peter bassill · operator
$ cve CVE-2021-3144 JSON

CVE-2021-3144

9.1
CRITICAL · CVSS 3.1 · EPSS 5.2% (pctl 92)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS5.24% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-613
On CISA KEVno
Public exploitnone known
Published2021-02-27
Last modified2026-06-17

Affected (3)

VendorProduct
debiandebian linux
fedoraprojectfedora
saltstacksalt

References

→ the Explorer  ·  watch your stack  ·  NVD