CVE-2022-22935

Name
CVE-2022-22935
Description
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/saltstack/salt/releases,
MISC https://repo.saltproject.io/
MISC https://saltproject.io/security_announcements/salt-security-advisory-release/,

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* salt >= 3002 < 3002.8
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* salt >= 3003 < 3003.4
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* salt >= 3004 < 3004.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
salt edge-community 3004.1-r0 Kevin Daudt <kdaudt@alpinelinux.org> fixed
salt 3.15-community 3004-r0 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
salt 3.16-community 3004.1-r0 Kevin Daudt <kdaudt@alpinelinux.org> fixed