github.com
https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2022-172.yaml CVE-2022-22935
LOW
SaltStack Salt Improper Authentication via Man in the Middle Attack
Record summary
CVE-2022-22935 has a selected CVSS score of 3.7 (low).
Description
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SaltStack Salt | CVE List | SaltStack Salt prior to 3002.8, 3003.4, 3004.1 | affected |
| GitHub Advisory | Before 3002.8 · Fixed in 3002.8 | affected | |
| 3003 to < 3003.4 · Fixed in 3003.4 | affected | ||
| 3004 to < 3004.1 · Fixed in 3004.1 | affected |
References
11github.com
https://github.com/saltstack/salt github.com
https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3002.8.rst github.com
https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3003.4.rst github.com
https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3004.1.rst github.com
https://github.com/saltstack/salt/releases%2C nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-22935 repo.saltproject.io
https://repo.saltproject.io/ saltproject.io
https://saltproject.io/security_announcements/salt-security-advisory-release saltproject.io
https://saltproject.io/security_announcements/salt-security-advisory-release/%2C GLSA-202310-22Vendor advisory
https://security.gentoo.org/glsa/202310-22