PT-2021-14842 · Saltstack+1 · Saltstack Salt+1

CVE-2021-22004

·

Published

2021-09-08

·

Updated

2022-11-25

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SaltStack Salt versions prior to 3003.3
Description An issue was discovered that allows a malicious actor to subvert the proper behavior of the minion software. This occurs when the salt minion installer accepts and uses a minion config file at C:saltconf if that file is in place before the installer is run.
Recommendations For versions prior to 3003.3, update to version 3003.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the C:saltconf directory to prevent malicious config files from being placed there.

Fix

Improper Authentication

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3218
CVE-2021-22004
GHSA-XF37-QCVF-7M57
PYSEC-2021-346

Affected Products

Alt Linux
Saltstack Salt