Vulnerabilities > CVE-2022-22967 - Incorrect Authorization vulnerability in Saltstack Salt

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
saltstack
CWE-863

Summary

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

Vulnerable Configurations

Part Description Count
Application
Saltstack
209

Common Weakness Enumeration (CWE)