FlawAtlas
Search the atlas
CVE-2021-21996 High

CVE-2021-21996

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

Exploit probability 3.5%
Published September 8, 2021
Required by Not available
Last source change July 8, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

46 explicit affected versions

PyPI salt

200 explicit affected versions

PyPI salt

200 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2021-21996

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

View original source
Open Source Vulnerabilities GHSA-pf7h-h2wq-m7pg

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

View original source
Open Source Vulnerabilities PYSEC-2021-318

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

View original source

05 / REFERENCES

Further evidence