CVE-2022-22935

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*

History

21 Dec 2023, 18:47

Type Values Removed Values Added
References () https://github.com/saltstack/salt/releases%2C - () https://github.com/saltstack/salt/releases%2C - Broken Link
References () https://saltproject.io/security_announcements/salt-security-advisory-release/%2C - () https://saltproject.io/security_announcements/salt-security-advisory-release/%2C - Broken Link
References () https://security.gentoo.org/glsa/202310-22 - () https://security.gentoo.org/glsa/202310-22 - Third Party Advisory

07 Nov 2023, 03:44

Type Values Removed Values Added
References
  • {'url': 'https://saltproject.io/security_announcements/salt-security-advisory-release/,', 'name': 'https://saltproject.io/security_announcements/salt-security-advisory-release/,', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://github.com/saltstack/salt/releases,', 'name': 'https://github.com/saltstack/salt/releases,', 'tags': ['Broken Link', 'Release Notes', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://saltproject.io/security_announcements/salt-security-advisory-release/%2C -
  • () https://github.com/saltstack/salt/releases%2C -

31 Oct 2023, 14:15

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202310-22 -

06 Apr 2022, 20:34

Type Values Removed Values Added
CWE CWE-287
CPE cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 3.7
First Time Saltstack salt
Saltstack
References (MISC) https://github.com/saltstack/salt/releases, - (MISC) https://github.com/saltstack/salt/releases, - Broken Link, Release Notes, Third Party Advisory
References (MISC) https://repo.saltproject.io/ - (MISC) https://repo.saltproject.io/ - Product
References (MISC) https://saltproject.io/security_announcements/salt-security-advisory-release/, - (MISC) https://saltproject.io/security_announcements/salt-security-advisory-release/, - Vendor Advisory

29 Mar 2022, 17:19

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-29 17:15

Updated : 2023-12-21 18:47


NVD link : CVE-2022-22935

Mitre link : CVE-2022-22935

CVE.ORG link : CVE-2022-22935


JSON object : View

Products Affected

saltstack

  • salt
CWE
CWE-287

Improper Authentication