Vulnerability Description
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Saltstack | Salt | >= 3002, < 3002.8 |
Related Weaknesses (CWE)
References
- https://github.com/saltstack/salt/releases%2CBroken Link
- https://repo.saltproject.io/Product
- https://saltproject.io/security_announcements/salt-security-advisory-release/%2CBroken Link
- https://security.gentoo.org/glsa/202310-22Third Party Advisory
- https://github.com/saltstack/salt/releases%2CBroken Link
- https://repo.saltproject.io/Product
- https://saltproject.io/security_announcements/salt-security-advisory-release/%2CBroken Link
- https://security.gentoo.org/glsa/202310-22Third Party Advisory
FAQ
What is CVE-2022-22935?
CVE-2022-22935 is a vulnerability with a CVSS score of 3.7 (LOW). An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonat...
How severe is CVE-2022-22935?
CVE-2022-22935 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22935?
Check the references section above for vendor advisories and patch information. Affected products include: Saltstack Salt.