CVE-2025-22241
13.06.2025, 07:15
File contents overwrite the VirtKey class is called when on-demand pillar data is requested and uses un-validated input to create paths to the pki directory. The functionality is used to auto-accept Minion authentication keys based on a pre-placed authorization file at a specific location and is present in the default configuration.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Vulnerability Media Exposure