CVE-2022-22934
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
02 / AFFECTED SOFTWARE
Affected packages
14 explicit affected versions
194 explicit affected versions
199 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/22xxx/CVE-2022-22934.json
- https://github.com/saltstack/salt/releases%2C
- https://nvd.nist.gov/vuln/detail/CVE-2022-22934
- https://repo.saltproject.io/
- https://saltproject.io/security_announcements/salt-security-advisory-release/%2C
- https://security.gentoo.org/glsa/202310-22
- https://github.com/advisories/GHSA-2q4g-wfm6-5fpm
- https://github.com/saltstack/salt/releases,
- https://saltproject.io/security_announcements/salt-security-advisory-release/,
- https://blog.cloudflare.com/future-proofing-saltstack
- https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2022-171.yaml
- https://github.com/saltstack/salt
- https://github.com/saltstack/salt/releases
- https://repo.saltproject.io