PT-2022-3075 · Saltstack+2 · Saltstack Salt+2
Published
2022-06-22
·
Updated
2023-12-21
·
CVE-2022-22967
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SaltStack Salt versions prior to 3002.9
SaltStack Salt versions prior to 3003.5
SaltStack Salt versions prior to 3004.2
Description
An issue was discovered in SaltStack Salt where PAM auth fails to reject locked accounts. This allows a previously authorized user whose account is locked to still run Salt commands when their account is locked, affecting both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.
Recommendations
For versions prior to 3002.9, update to version 3002.9 or later to resolve the issue.
For versions prior to 3003.5, update to version 3003.5 or later to resolve the issue.
For versions prior to 3004.2, update to version 3004.2 or later to resolve the issue.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Saltstack Salt
Suse