Lucene search

K
cvelistVmwareCVELIST:CVE-2022-22967
HistoryJun 22, 2022 - 12:00 a.m.

CVE-2022-22967

2022-06-2200:00:00
vmware
www.cve.org
7
saltstack salt
account lock
pam authentication

AI Score

8.7

Confidence

High

EPSS

0.002

Percentile

64.9%

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "SaltStack Salt",
    "versions": [
      {
        "version": "SaltStack Salt prior to 3002.9, 3003.5, 3004.2",
        "status": "affected"
      }
    ]
  }
]

AI Score

8.7

Confidence

High

EPSS

0.002

Percentile

64.9%