CVE-2022-22934: High severity saltstack vulnerability
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22934?
CVE-2022-22934 is a vulnerability discovered in SaltStack Salt in versions before 3002.8, 3003.4, and 3004.1.
What is the severity of CVE-2022-22934?
The severity of CVE-2022-22934 is classified as high with a CVSS score of 8.8.
How does CVE-2022-22934 affect SaltStack Salt?
CVE-2022-22934 affects Salt Masters in versions before 3002.8, 3003.4, and 3004.1 by not signing pillar data with the minion's public key, allowing attackers to substitute arbitrary pillar data.
What is the remedy for CVE-2022-22934?
To remediate CVE-2022-22934, upgrade SaltStack Salt to version 3003.4 or later.
Where can I find more information about CVE-2022-22934?
For more information about CVE-2022-22934, you can refer to the following sources: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-22934), [Cloudflare Blog](https://blog.cloudflare.com/future-proofing-saltstack/), [SaltStack Salt Releases](https://github.com/saltstack/salt/releases).