Critical severity9.1NVD Advisory· Published Feb 27, 2021· Updated Jun 17, 2026
CVE-2021-3144
CVE-2021-3144
Description
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
saltPyPI | < 2015.8.13 | 2015.8.13 |
saltPyPI | >= 2016.3.0, < 2016.11.5 | 2016.11.5 |
saltPyPI | >= 2016.11.7, < 2016.11.10 | 2016.11.10 |
saltPyPI | >= 2017.5.0, < 2017.7.8 | 2017.7.8 |
saltPyPI | >= 2018.2.0, <= 2018.3.5 | — |
saltPyPI | >= 3000, < 3000.7 | 3000.7 |
saltPyPI | >= 3001, < 3001.5 | 3001.5 |
saltPyPI | >= 3002, < 3002.3 | 3002.3 |
saltPyPI | >= 2019.2.0, < 2019.2.8 | 2019.2.8 |
Affected products
39cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- SaltStack/Saltdescription
- ghsa-coords31 versionspkg:pypi/saltpkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/py26-compat-salt&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/py26-compat-salt&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/release-notes-susemanager&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/release-notes-susemanager&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/release-notes-susemanager-proxy&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/release-notes-susemanager-proxy&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/release-notes-susemanager-proxy&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/release-notes-susemanager-proxy&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/salt&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2012%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/salt&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/salt&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/salt&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/salt&distro=SUSE%20Manager%20Server%204.0
< 2015.8.13+ 30 more
- (no CPE)range: < 2015.8.13
- (no CPE)range: < 3000-lp152.3.27.1
- (no CPE)range: < 2016.11.10-10.22.1
- (no CPE)range: < 2016.11.10-6.8.1
- (no CPE)range: < 4.0.12.1-3.68.1
- (no CPE)range: < 4.1.5.1-3.38.1
- (no CPE)range: < 4.0.12.1-0.16.52.1
- (no CPE)range: < 4.1.5.1-3.26.1
- (no CPE)range: < 4.0.12.1-0.16.52.1
- (no CPE)range: < 4.1.5.1-3.26.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-5.106.1
- (no CPE)range: < 3000-5.106.1
- (no CPE)range: < 3000-46.129.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-46.129.1
- (no CPE)range: < 2016.11.10-43.69.1
- (no CPE)range: < 2016.11.10-43.69.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-5.106.1
- (no CPE)range: < 3000-5.106.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-46.129.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-24.1
- (no CPE)range: < 3000-24.1
Patches
Vulnerability mechanics
References
23- github.com/advisories/GHSA-w2hr-3mc8-46ghghsaADVISORY
- github.com/saltstack/salt/releasesnvdThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2021/11/msg00009.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVB/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FUGLOJ6NXLCIFRD2JTXBYQEMAEF2B6XH/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YOGNT2XWPOYV7YT75DN7PS4GIYWFKOK5/nvdMailing ListThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2021-3144ghsaADVISORY
- saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/nvdVendor Advisory
- security.gentoo.org/glsa/202103-01nvdThird Party AdvisoryWEB
- security.gentoo.org/glsa/202310-22nvdThird Party AdvisoryWEB
- www.debian.org/security/2021/dsa-5011nvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2021-54.yamlghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/CHANGELOG.mdghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3000.7.rstghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3001.5.rstghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3002.3.rstghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVBghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FUGLOJ6NXLCIFRD2JTXBYQEMAEF2B6XHghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YOGNT2XWPOYV7YT75DN7PS4GIYWFKOK5ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/7GRVZ5WAEI3XFN2BDTL6DDXFS5HYSDVBghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/FUGLOJ6NXLCIFRD2JTXBYQEMAEF2B6XHghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/YOGNT2XWPOYV7YT75DN7PS4GIYWFKOK5ghsaWEB
- saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25ghsaWEB
News mentions
0No linked articles in our index yet.