← Back to CVE List

CVE-2021-3148

Published: 2021-02-27T05:15Z
Last Modified: 2024-11-21T06:20Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt