Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18249 | Salt's file contents overwrite the VirtKey class |
Github GHSA |
GHSA-7f3f-x5f5-79gw | Salt's file contents overwrite the VirtKey class |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 |
Fri, 13 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Jun 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “authorization file” at a specific location and is present in the default configuration. | |
| Title | CVE-2025-22241 salt advisory | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-06-17T17:26:12.653Z
Reserved: 2025-01-02T04:30:06.833Z
Link: CVE-2025-22241
Updated: 2025-06-13T15:24:31.165Z
Status : Deferred
Published: 2025-06-13T07:15:21.567
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-22241
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA