CVE-2022-22941
Published on: Not Yet Published
Last Modified on: 04/06/2022 08:25:00 PM UTC
Certain versions of Salt from Saltstack contain the following vulnerability:
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.
- CVE-2022-22941 has been assigned by
secu[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Salt Project Package Repo | repo.saltproject.io text/html |
![]() |
Salt Security Advisory Release – Salt Project | saltproject.io text/html |
![]() |
github.com text/plain Inactive LinkNot Archived |
![]() |
Related QID Numbers
- 502365 Alpine Linux Security Update for salt
- 751945 SUSE Enterprise Linux Security Update for salt (SUSE-SU-2022:1060-1)
- 751948 SUSE Enterprise Linux Security Update for salt (SUSE-SU-2022:1058-1)
- 751949 SUSE Enterprise Linux Security Update for salt (SUSE-SU-2022:1057-1)
- 751953 OpenSUSE Security Update for salt (openSUSE-SU-2022:1059-1)
- 752018 SUSE Enterprise Linux Security Update for salt (SUSE-SU-2022:1059-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Saltstack | Salt | All | All | All | All |
- cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-22941 : An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configur… twitter.com/i/web/status/1… | 2022-03-29 17:07:37 |
![]() |
CVE-2022-22941 | 2022-03-29 18:39:02 |