Description

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

SaltStack Salt

CVE ListSaltStack Salt prior to 3002.9, 3003.5, 3004.2affected
GitHub AdvisoryBefore 3002.9 · Fixed in 3002.9affected
3003.0 to < 3003.5 · Fixed in 3003.5affected
3004.0 to < 3004.2 · Fixed in 3004.2affected

References

8