github.com
https://github.com/advisories/GHSA-fpxm-fprw-6hxj CVE-2022-22967
Salt's PAM auth fails to reject locked accounts
Description
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SaltStack Salt | CVE List | SaltStack Salt prior to 3002.9, 3003.5, 3004.2 | affected |
| GitHub Advisory | Before 3002.9 · Fixed in 3002.9 | affected | |
| 3003.0 to < 3003.5 · Fixed in 3003.5 | affected | ||
| 3004.0 to < 3004.2 · Fixed in 3004.2 | affected |
References
8github.com
https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2022-210.yaml github.com
https://github.com/saltstack/salt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-22967 repo.saltproject.io
https://repo.saltproject.io/ saltproject.io
https://saltproject.io/security_announcements/salt-security-advisory-release-june-21st-2022/%2C saltproject.io
https://saltproject.io/security_announcements/salt-security-advisory-release-june-21st-2022/, GLSA-202310-22Vendor advisory
https://security.gentoo.org/glsa/202310-22