An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1
Published Mar 29, 2022
8.8
HIGHCVSS 3.1
EPSS 1.35%
Description
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.
Affected products
- Vendor n/a Product SaltStack Salt Defaultunknown
Affected
- SaltStack Salt prior to 3002.8, 3003.4, 3004.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | SaltStack Salt | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0273 Advisory
- https://github.com/advisories/GHSA-qcr3-hr2f-6557 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2022-174.yaml
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3002.8.rst#L31
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3003.4.rst#L32
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3004.1.rst#L30
- https://github.com/saltstack/salt/releases%2C Broken Link
- https://nvd.nist.gov/vuln/detail/CVE-2022-22941
- https://repo.saltproject.io Product
- https://saltproject.io/security_announcements/salt-security-advisory-release/%2C Broken Link
- https://security.gentoo.org/glsa/202310-22 vendor-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub