An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
References
Link | Resource |
---|---|
https://github.com/saltstack/salt/releases, | Broken Link Release Notes Third Party Advisory |
https://repo.saltproject.io/ | Product |
https://saltproject.io/security_announcements/salt-security-advisory-release/, | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-03-29 10:15
Updated : 2022-04-06 13:48
NVD link : CVE-2022-22934
Mitre link : CVE-2022-22934
JSON object : View
CWE
CWE-347
Improper Verification of Cryptographic Signature
Products Affected
saltstack
- salt