Description
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be re-played. A sufficient craft attacker could gain root access on minion under certain scenarios.
Published: 2022-03-29
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5r3f-3m3j-wcj2 SaltStack Salt Authentication Bypass by Capture-replay
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2025-05-05T16:28:34.495Z

Reserved: 2022-01-10T00:00:00.000Z

Link: CVE-2022-22936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-29T17:15:15.273

Modified: 2025-05-05T17:17:54.440

Link: CVE-2022-22936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses