Lucene search

K
osvGoogleOSV:CVE-2022-22934
HistoryMar 29, 2022 - 5:15 p.m.

CVE-2022-22934

2022-03-2917:15:15
Google
osv.dev
11
saltstack salt
version 3002.8
version 3003.4
version 3004.1
salt masters
pillar data
public key
attackers
security issue

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

43.9%

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

43.9%