
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-25315 is an Improper Authentication vulnerability (CWE-287) that affects SUSE Linux Enterprise Server 15 SP 3 and openSUSE Tumbleweed. The vulnerability allows local attackers to execute arbitrary code via salt without the need to specify valid credentials (Debian Tracker).
The vulnerability was caused by an overlapping of upstream patch and one of SUSE's patches in the salt component. This issue affects SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3 and openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions (SUSE Bugzilla).
The vulnerability allows local attackers to execute arbitrary code without requiring valid credentials, potentially leading to unauthorized system access and code execution (NVD).
The vulnerability requires local access to the system to be exploited. It was confirmed that this issue was specific to SUSE implementations and did not affect the upstream salt project (SUSE Bugzilla).
The issue has been fixed in salt version 3002.2-3 for SUSE Linux Enterprise Server 15 SP 3 and version 3002.2-2.1 for openSUSE Tumbleweed. Users are advised to upgrade to these versions or later (SUSE Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."