Vulnerabilities > CVE-2022-22934 - Unspecified vulnerability in Saltstack Salt
Attack vector
ADJACENT_NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH low complexity
saltstack
Summary
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 13 |