PT-2022-15745 · Saltstack+2 · Saltstack Salt+2

Published

2022-03-29

·

Updated

2023-12-21

·

CVE-2022-22941

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SaltStack Salt versions prior to 3002.8 SaltStack Salt versions prior to 3003.4 SaltStack Salt versions prior to 3004.1
Description An issue was discovered in SaltStack Salt when configured as a Master-of-Masters with a publisher acl. If a user configured in the publisher acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid. This allows configured users to target any of the minions connected to the syndic with their configured commands, effectively bypassing permissions and publishing authorized commands to any configured minion.
Recommendations For versions prior to 3002.8, update to version 3002.8 or later. For versions prior to 3003.4, update to version 3003.4 or later. For versions prior to 3004.1, update to version 3004.1 or later. As a temporary workaround, consider restricting access to the publisher acl and syndic master configurations to minimize the risk of exploitation.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3177
ALT-PU-2022-3214
ALT-PU-2022-3218
CVE-2022-22941
GHSA-QCR3-HR2F-6557
OPENSUSE-SU-2022:1059-1
OPENSUSE-SU-2022_1059-1
OPENSUSE-SU-2024:11970-1
PYSEC-2022-174
SUSE-FU-2022:2042-1
SUSE-FU-2022:2135-1
SUSE-RU-2022:1384-1
SUSE-RU-2022:1385-1
SUSE-RU-2022:1389-1
SUSE-RU-2022:1391-1
SUSE-RU-2022:1392-1
SUSE-SU-2022:1049-1
SUSE-SU-2022:1050-1
SUSE-SU-2022:1051-1
SUSE-SU-2022:1057-1
SUSE-SU-2022:1058-1
SUSE-SU-2022:1059-1
SUSE-SU-2022:1060-1
SUSE-SU-2022:1514-1
SUSE-SU-2022:1531-1
SUSE-SU-2022:1536-1
SUSE-SU-2022:1545-1

Affected Products

Alt Linux
Saltstack Salt
Suse