PT-2025-25391 · Saltstack+3 · Saltstack Salt+3
Published
2025-01-02
·
Updated
2025-08-19
·
CVE-2025-22236
CVSS v3.1
8.1
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
SaltStack Salt versions 3007.0 and later
Description
The issue concerns an authorization bypass in the Minion event bus. An attacker with access to a minion key can craft a message to potentially execute a job on other minions.
Recommendations
For versions 3007.0 and later, update to a version that includes a fix for the authorization bypass issue in the Minion event bus.
Fix
Improper Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Red Os
Saltstack Salt
Suse