Lucene search

K
osvGoogleOSV:PYSEC-2022-171
HistoryMar 29, 2022 - 5:15 p.m.

PYSEC-2022-171

2022-03-2917:15:00
Google
osv.dev
14
saltstack salt
version 3002.8
version 3003.4
version 3004.1
pillar data
minion’s public key
attackers

EPSS

0.001

Percentile

43.9%

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.