CVE-2021-22004: Race Condition
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.
Other sources
The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behavior of the given minion software.
— Salt Project
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-22004?
CVE-2021-22004 is a vulnerability in SaltStack Salt before version 3003.3 that allows a malicious actor to subvert the proper behavior of the Salt minion software.
How severe is CVE-2021-22004?
CVE-2021-22004 has a severity rating of 6.4, which is considered medium.
What software is affected by CVE-2021-22004?
SaltStack Salt versions before 3003.3 are affected by CVE-2021-22004.
How can I fix CVE-2021-22004?
To fix CVE-2021-22004, update SaltStack Salt to version 3003.3 or later.
Where can I find more information about CVE-2021-22004?
More information about CVE-2021-22004 can be found at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-22004), [Fedora Project](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BUWUF5VTENNP2ZYZBVFKPSUHLKLUBD5/), [Fedora Project](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVT7M4YLZRLWWQ6SGRK3C6TOF4FXOXT/)