PT-2021-14842 · Saltstack+1 · Saltstack Salt+1

Published

2021-09-08

·

Updated

2022-11-25

·

CVE-2021-22004

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SaltStack Salt versions prior to 3003.3
Description An issue was discovered that allows a malicious actor to subvert the proper behavior of the minion software. This occurs when the salt minion installer accepts and uses a minion config file at C:saltconf if that file is in place before the installer is run.
Recommendations For versions prior to 3003.3, update to version 3003.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the C:saltconf directory to prevent malicious config files from being placed there.

Fix

Improper Authentication

Race Condition

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3218
CVE-2021-22004
GHSA-XF37-QCVF-7M57
PYSEC-2021-346

Affected Products

Alt Linux
Saltstack Salt