Vulnerabilities > CVE-2021-3144 - Insufficient Session Expiration vulnerability in multiple products

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
saltstack
fedoraproject
debian
CWE-613
critical

Summary

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

Vulnerable Configurations

Part Description Count
Application
Saltstack
180
OS
Fedoraproject
3
OS
Debian
3

Common Weakness Enumeration (CWE)