CVE-2022-22934
29.03.2022, 17:15
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minions public key, which can result in attackers substituting arbitrary pillar data.Enginsight
Vendor | Product | Version |
---|---|---|
saltstack | salt | 3002 ≤ 𝑥 < 3002.8 |
saltstack | salt | 3003 ≤ 𝑥 < 3003.4 |
saltstack | salt | 3004 ≤ 𝑥 < 3004.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References