CVE-2022-22935

Severity
3.7LOW
EPSS
0.1%
top 78.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 29
Latest updateMar 30

Description

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4

Affected Packages3 packages

NVDsaltstack/salt30023002.8+2
CVEListV5saltstack_saltSaltStack Salt prior to 3002.8, 3003.4, 3004.1
PyPIsalt30033003.4+2

🔴Vulnerability Details

4
GHSA
SaltStack Salt Improper Authentication via Man in the Middle Attack2022-03-30
OSV
SaltStack Salt Improper Authentication via Man in the Middle Attack2022-03-30
OSV
CVE-2022-22935: An issue was discovered in SaltStack Salt in versions before 30022022-03-29
CVEList
CVE-2022-22935: An issue was discovered in SaltStack Salt in versions before 30022022-03-29