FlawAtlas
Search the atlas
CVE-2021-3148 Critical

CVE-2021-3148

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.

Exploit probability 8.2%
Published February 27, 2021
Required by Not available
Last source change June 10, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

95 explicit affected versions

PyPI salt

159 explicit affected versions

PyPI salt

168 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2021-3148

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.

View original source
Open Source Vulnerabilities PYSEC-2021-55

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.

View original source
Open Source Vulnerabilities GHSA-ghc2-hx3w-jqmp

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in `salt.utils.thin.gen_thin()` command injection because of different handling of single versus double quotes. This is related to `salt/utils/thin.py`.

View original source

05 / REFERENCES

Further evidence