{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "Command injection in the snapper module",
    "tracking": {
      "current_release_date": "2026-08-11T14:55:45+00:00",
      "generator": {
        "date": "2026-08-11T14:55:45+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-31607",
      "initial_release_date": "2021-04-23T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:55:45+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Ceph Storage 2.5",
            "product": {
              "name": "Red Hat Ceph Storage 2.5",
              "product_id": "ceph-2",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:ceph_storage:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "salt",
            "product": {
              "name": "salt",
              "product_id": "salt",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/salt"
              }
            }
          },
          {
            "category": "product_version",
            "name": "salt-minion",
            "product": {
              "name": "salt-minion",
              "product_id": "salt-minion",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/salt-minion"
              }
            }
          },
          {
            "category": "product_version",
            "name": "salt",
            "product": {
              "name": "salt",
              "product_id": "salt.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/salt?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "salt as a component of Red Hat Ceph Storage 2.5",
          "product_id": "ceph-2:salt"
        },
        "product_reference": "salt",
        "relates_to_product_reference": "ceph-2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "salt-minion as a component of Red Hat Ceph Storage 2.5",
          "product_id": "ceph-2:salt-minion"
        },
        "product_reference": "salt-minion",
        "relates_to_product_reference": "ceph-2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "salt.src as a component of Red Hat Ceph Storage 2.5",
          "product_id": "ceph-2:salt.src"
        },
        "product_reference": "salt.src",
        "relates_to_product_reference": "ceph-2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-31607",
      "cwe": {
        "id": "CWE-77",
        "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')"
      },
      "discovery_date": "2021-04-23T00:00:00+00:00",
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Salt. A command injection vulnerability occurs in the snapper module that allows local privilege escalation on a minion. This attack requires the creation of a file with a pathname that is backed up by snapper, with the master calling the snapper.diff function. Snapper.diff executes the popen unsafely. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "ceph-2:salt",
          "ceph-2:salt-minion",
          "ceph-2:salt.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-31607"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31607"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-31607"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Out of support scope",
          "product_ids": [
            "ceph-2:salt",
            "ceph-2:salt-minion",
            "ceph-2:salt.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 7.8,
            "baseSeverity": "HIGH"
          },
          "products": [
            "ceph-2:salt",
            "ceph-2:salt-minion",
            "ceph-2:salt.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "ceph-2:salt",
            "ceph-2:salt-minion",
            "ceph-2:salt.src"
          ]
        }
      ],
      "title": "Command injection in the snapper module"
    }
  ]
}