PT-2022-15743 · Saltstack+2 · Saltstack Salt+2

Published

2022-03-29

·

Updated

2023-12-21

·

CVE-2022-22935

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions SaltStack Salt versions prior to 3002.8 SaltStack Salt versions prior to 3003.4 SaltStack Salt versions prior to 3004.1
Description An issue in SaltStack Salt allows a man-in-the-middle (MiTM) attacker to impersonate a master and cause a minion authentication denial of service. This can force a minion process to stop.
Recommendations For versions prior to 3002.8, update to version 3002.8 or later. For versions prior to 3003.4, update to version 3003.4 or later. For versions prior to 3004.1, update to version 3004.1 or later.

Fix

DoS

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3177
ALT-PU-2022-3214
ALT-PU-2022-3218
CVE-2022-22935
GHSA-CVCC-5X92-GMHC
OPENSUSE-SU-2022:1059-1
OPENSUSE-SU-2022_1059-1
OPENSUSE-SU-2024:11970-1
PYSEC-2022-172
SUSE-FU-2022:2042-1
SUSE-FU-2022:2135-1
SUSE-RU-2022:1385-1
SUSE-RU-2022:1389-1
SUSE-RU-2022:1391-1
SUSE-RU-2022:1392-1
SUSE-SU-2022:1049-1
SUSE-SU-2022:1050-1
SUSE-SU-2022:1051-1
SUSE-SU-2022:1057-1
SUSE-SU-2022:1058-1
SUSE-SU-2022:1059-1
SUSE-SU-2022:1060-1
SUSE-SU-2022:1514-1
SUSE-SU-2022:1536-1
SUSE-SU-2022:1545-1

Affected Products

Alt Linux
Saltstack Salt
Suse