Record summary

CVE-2022-22935 has a selected CVSS score of 3.7 (low).

Description

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

SaltStack Salt

CVE ListSaltStack Salt prior to 3002.8, 3003.4, 3004.1affected
GitHub AdvisoryBefore 3002.8 · Fixed in 3002.8affected
3003 to < 3003.4 · Fixed in 3003.4affected
3004 to < 3004.1 · Fixed in 3004.1affected

References

11