CVE Vulnerabilities

CVE-2022-22934

Published: Mar 29, 2022 | Modified: Dec 21, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.

Affected Software

Name Vendor Start Version End Version
Salt Saltstack 3002 (including) 3002.8 (excluding)
Salt Saltstack 3003 (including) 3003.4 (excluding)
Salt Saltstack 3004 (including) 3004.1 (excluding)

References