Description
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
References (4)
Core 4
Core References
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202310-22
Broken Link
https://github.com/saltstack/salt/releases%2C
Product
https://repo.saltproject.io/
Scores
CVSS v3
8.8
EPSS
0.0086
EPSS Percentile
54.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (2)
pypi/salt
0 - 3002.8PyPI
saltstack/salt
3002 - 3002.8
Published
Mar 29, 2022
Tracked Since
Feb 18, 2026