PT-2022-3075 · Saltstack +2 · Saltstack Salt +2
Published
2022-06-22
·
Updated
2023-12-21
·
CVE-2022-22967
8.8
High
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SaltStack Salt versions prior to 3002.9
SaltStack Salt versions prior to 3003.5
SaltStack Salt versions prior to 3004.2
Description:
An issue was discovered in SaltStack Salt where PAM auth fails to reject locked accounts. This allows a previously authorized user whose account is locked to still run Salt commands when their account is locked, affecting both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.
Recommendations:
For versions prior to 3002.9, update to version 3002.9 or later to resolve the issue.
For versions prior to 3003.5, update to version 3003.5 or later to resolve the issue.
For versions prior to 3004.2, update to version 3004.2 or later to resolve the issue.
Exploit
Fix
Improper Authorization
Incorrect Authorization
Related Identifiers
Affected Products
References · 110
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/saltstack_salt_api_cmd_exec.rb⭐ 35561 🔗 14312 · Exploit
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/saltstack_salt_wheel_async_rce.rb⭐ 35561 🔗 14312 · Exploit
- 🔥 https://github.com/Immersive-Labs-Sec/CVE-2021-25281⭐ 26 🔗 9 · Exploit
- 🔥 https://github.com/stealthcopter/CVE-2020-28243⭐ 17 🔗 4 · Exploit
- 🔥❌ https://github.com/SkyBulk/CVE-2021-25281 · Exploit, Deleted
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33226 · Security Note
- https://osv.dev/vulnerability/PYSEC-2022-210 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22967 · Security Note
- https://bdu.fstec.ru/vul/2021-01900 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28243 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17490 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16846 · Security Note
- https://bdu.fstec.ru/vul/2022-07060 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35662 · Security Note
- https://osv.dev/vulnerability/SUSE-SU-2022:2178-1 · Vendor Advisory