Security Advisory

CVE-2021-3197

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-02-27 00:00:00
Last updated 2024-08-03 16:45:51
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.