An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
References
Link | Resource |
---|---|
https://github.com/saltstack/salt/releases%2C | Broken Link |
https://repo.saltproject.io/ | Product |
https://saltproject.io/security_announcements/salt-security-advisory-release/%2C | Broken Link |
https://security.gentoo.org/glsa/202310-22 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Dec 2023, 18:45
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
06 Apr 2022, 20:48
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 5.8
v3 : 8.8 |
CWE | CWE-347 | |
References | (MISC) https://saltproject.io/security_announcements/salt-security-advisory-release/, - Vendor Advisory | |
References | (MISC) https://repo.saltproject.io/ - Product | |
References | (MISC) https://github.com/saltstack/salt/releases, - Broken Link, Release Notes, Third Party Advisory |
29 Mar 2022, 17:19
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-03-29 17:15
Updated : 2024-02-04 22:29
NVD link : CVE-2022-22934
Mitre link : CVE-2022-22934
CVE.ORG link : CVE-2022-22934
JSON object : View
Products Affected
saltstack
- salt
CWE