CVE-2022-22967
23.06.2022, 17:15
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.Enginsight
Vendor | Product | Version |
---|---|---|
saltstack | salt | 𝑥 < 3002.9 |
saltstack | salt | 3003 ≤ 𝑥 < 3003.5 |
saltstack | salt | 3004 ≤ 𝑥 < 3004.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References