CVE-2022-22935: Medium severity saltstack vulnerability
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
Affected Software
Remediation
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22935?
CVE-2022-22935 is a vulnerability in SaltStack Salt that allows a minion authentication denial of service attack.
What versions of SaltStack Salt are affected by CVE-2022-22935?
Versions before 3002.8, 3003.4, and 3004.1 of SaltStack Salt are affected by CVE-2022-22935.
How can a minion authentication denial of service attack be exploited using CVE-2022-22935?
A MiTM attacker can impersonate a master and force a minion process to stop, causing the denial of service.
What is the severity of CVE-2022-22935?
CVE-2022-22935 has a severity level of medium (3.7).
Where can I find more information about CVE-2022-22935?
More information about CVE-2022-22935 can be found in the SaltStack Salt releases, the Salt project's repository, and the Salt security advisory release.