CVE-2022-22934

CWE-3475 documents4 sources
Severity
8.8HIGH
EPSS
0.1%
top 68.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 29
Latest updateMar 30

Description

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDsaltstack/salt30023002.8+2
CVEListV5saltstack_saltSaltStack Salt prior to 3002.8, 3003.4, 3004.1
PyPIsalt30043004.1+2

🔴Vulnerability Details

4
GHSA
SaltStack Improper Verification of Cryptographic Signature2022-03-30
OSV
SaltStack Improper Verification of Cryptographic Signature2022-03-30
CVEList
CVE-2022-22934: An issue was discovered in SaltStack Salt in versions before 30022022-03-29
OSV
CVE-2022-22934: An issue was discovered in SaltStack Salt in versions before 30022022-03-29