HIGH
CVE-2025-22239 salt advisory
Published Jun 13, 2025
8.1
HIGHCVSS 3.1
EPSS 0.18%
Description
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.
Affected products
-
- Version 3006.xStatusaffectedConstraints<3006.12
- Version 3007.xStatusaffectedConstraints<3007.4
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://docs.saltproject.io/en/3006/topics/releases/3006.12.html
- https://docs.saltproject.io/en/3007/topics/releases/3007.4.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18251 Advisory
- https://github.com/advisories/GHSA-c46w-gr7f-jm2p Advisory
- https://github.com/saltstack/salt/commit/41d834bf800d86fc496e4fac2d3875fc2aca7c62
- https://nvd.nist.gov/vuln/detail/CVE-2025-22239
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Jun 13, 2025
Updated Jun 13, 2025
Reserved Jan 2, 2025
Link CVE-2025-22239
CISA Vulnrichment
Updated Jun 13, 2025
ENISA EUVD
EUVD-2025-18251 GHSA-C46W-GR7F-JM2P Assigner vmware
Published Jun 13, 2025
Updated Jun 13, 2025
Exploited since n/a
Link EUVD-2025-18251