CVE Vulnerabilities

CVE-2022-22935

Improper Authentication

Published: Mar 29, 2022 | Modified: Dec 21, 2023
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Salt Saltstack 3002 (including) 3002.8 (excluding)
Salt Saltstack 3003 (including) 3003.4 (excluding)
Salt Saltstack 3004 (including) 3004.1 (excluding)
Salt Ubuntu bionic *
Salt Ubuntu impish *
Salt Ubuntu kinetic *
Salt Ubuntu trusty *
Salt Ubuntu xenial *

Potential Mitigations

References