Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-31607
HistoryApr 23, 2021 - 6:15 a.m.

Command injection

2021-04-2306:15:00
PRIOn knowledge base
www.prio-n.com
5

7.9 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.9%

In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).

CPENameOperatorVersion
fedoraeq33
fedoraeq34
fedoraeq35
saltge2016.9
saltle3002.6

7.9 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.9%