← Back

CVE-2022-22936

nvd nist
Published: Mar 29, 2022Modified: May 5, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be re-played. A sufficient craft attacker could gain root access on minion under certain scenarios.

Affected (3)

Products: Saltstack: Salt
1 product
Salt
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Saltstack
From 3002 to 3002.8
From 3003 to 3003.4
From 3004 to 3004.1

References (8)

Source: security@vmware.com
Broken Link
Source: security@vmware.com
Product
Source: security@vmware.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.