CVE-2022-22934

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-22934
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22934.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-22934
Aliases
Published
2022-03-29T17:15:15Z
Modified
2024-05-29T21:34:53Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.

References

Affected packages

Git / github.com/saltstack/salt

Affected ranges

Type
GIT
Repo
https://github.com/saltstack/salt
Events