ZeroHour

CVE-2021-25283

CVSS 3.1
9.8 critical
EPSS
11%p95
Published
()
Modified
Description

An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.

Vendors
saltstackfedoraprojectdebian
Products
salt, fedora, debian linux
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.