FlawAtlas
Search the atlas
CVE-2021-3144 Critical

CVE-2021-3144

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

Exploit probability 5.2%
Published February 27, 2021
Required by Not available
Last source change June 10, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

95 explicit affected versions

PyPI salt

159 explicit affected versions

PyPI salt

168 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2021-3144

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

View original source
Open Source Vulnerabilities PYSEC-2021-54

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

View original source
Open Source Vulnerabilities GHSA-w2hr-3mc8-46gh

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

View original source

05 / REFERENCES

Further evidence