CVE-2021-22004

MEDIUM

SaltStack Salt < 3003.3 - Race Condition via Minion Config File

Title source: llm
STIX 2.1

Description

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

Scores

CVSS v3 6.4
EPSS 0.0014
EPSS Percentile 33.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (5)
fedoraproject/fedora 33
fedoraproject/fedora 34
fedoraproject/fedora 35
pypi/salt 0 - 3003.3PyPI
saltstack/salt < 3000.3
Published Sep 08, 2021
Tracked Since Feb 18, 2026