Lucene search

K
osvGoogleOSV:GHSA-2Q4G-WFM6-5FPM
HistoryMar 30, 2022 - 12:00 a.m.

SaltStack Improper Verification of Cryptographic Signature

2022-03-3000:00:20
Google
osv.dev
7
saltstack
cryptographic signature
salt masters

EPSS

0.001

Percentile

43.9%

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.