alpine · CVE-2021-21996

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2021-21996: 1 source package rows (salt); 4 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 4.

Description:

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

cvelogic Threat Intelligence