CVE-2025-22242
Severity
5.6MEDIUM
EPSS
0.1%
top 67.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Description
Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method which is exposed to all minions. The un-sanitized input value “jid” is used to construct a path which is then opened for reading. An attacker could exploit this vulnerabilities by attempting to read from a filename that will not return any data, e.g. by targeting a pipe node on the proc file system.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:HExploitability: 0.3 | Impact: 5.2