An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2015.8.10"
},
{
"introduced": "2015.8.11"
},
{
"fixed": "2015.8.13"
},
{
"introduced": "2016.3.0"
},
{
"fixed": "2016.3.4"
},
{
"introduced": "2016.3.5"
},
{
"fixed": "2016.3.6"
},
{
"introduced": "2016.3.7"
},
{
"fixed": "2016.3.8"
},
{
"introduced": "2016.11.4"
},
{
"fixed": "2016.11.5"
},
{
"introduced": "2016.11.7"
},
{
"fixed": "2016.11.10"
},
{
"introduced": "2019.2.0"
},
{
"fixed": "2019.2.5"
},
{
"introduced": "2019.2.6"
},
{
"fixed": "2019.2.8"
},
{
"introduced": "3000"
},
{
"fixed": "3000.6"
},
{
"introduced": "3001"
},
{
"fixed": "3001.4"
},
{
"introduced": "3002"
},
{
"fixed": "3002.5"
}
]
}[
{
"events": [
{
"introduced": "2016.3.9"
},
{
"fixed": "2016.11.3"
}
]
},
{
"events": [
{
"introduced": "2017.5.0"
},
{
"fixed": "2017.7.8"
}
]
},
{
"events": [
{
"introduced": "2018.2.0"
},
{
"last_affected": "2018.3.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "34"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3197.json"