Description
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0226 | An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\\salt\\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software. |
Github GHSA |
GHSA-xf37-qcvf-7m57 | Improper Authentication in SaltStack Salt |
References
History
No history.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-03T18:30:23.738Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-22004
No data.
Status : Modified
Published: 2021-09-08T15:15:12.723
Modified: 2024-11-21T05:49:25.440
Link: CVE-2021-22004
OpenCVE Enrichment
No data.
EUVD
Github GHSA