PT-2021-14842 · Saltstack+1 · Saltstack Salt+1
Published
2021-09-08
·
Updated
2022-11-25
·
CVE-2021-22004
CVSS v4.0
7.5
High
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SaltStack Salt versions prior to 3003.3
Description
An issue was discovered that allows a malicious actor to subvert the proper behavior of the minion software. This occurs when the salt minion installer accepts and uses a minion config file at C:saltconf if that file is in place before the installer is run.
Recommendations
For versions prior to 3003.3, update to version 3003.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the C:saltconf directory to prevent malicious config files from being placed there.
Fix
Improper Authentication
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Saltstack Salt