Количество 15
Количество 15
CVE-2022-22941
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.
CVE-2022-22941
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.
CVE-2022-22941
An issue was discovered in SaltStack Salt in versions before 3002.8, 3 ...
GHSA-qcr3-hr2f-6557
SaltStack Salt Permissions Bypass
openSUSE-SU-2022:1059-1
Security update for salt
SUSE-SU-2022:1060-1
Security update for salt
SUSE-SU-2022:1059-1
Security update for salt
SUSE-SU-2022:1058-1
Security update for salt
SUSE-SU-2022:1057-1
Security update for salt
SUSE-SU-2022:1051-1
Security update for salt
SUSE-RU-2022:1392-1
Recommended update for salt
SUSE-RU-2022:1391-1
Recommended update for salt
SUSE-RU-2022:1389-1
Recommended update for salt
SUSE-RU-2022:1385-1
Recommended update for Salt
SUSE-RU-2022:1384-1
Recommended update for Salt
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-22941 An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
CVE-2022-22941 An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
CVE-2022-22941 An issue was discovered in SaltStack Salt in versions before 3002.8, 3 ... | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-qcr3-hr2f-6557 SaltStack Salt Permissions Bypass | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
openSUSE-SU-2022:1059-1 Security update for salt | почти 4 года назад | |||
SUSE-SU-2022:1060-1 Security update for salt | почти 4 года назад | |||
SUSE-SU-2022:1059-1 Security update for salt | почти 4 года назад | |||
SUSE-SU-2022:1058-1 Security update for salt | почти 4 года назад | |||
SUSE-SU-2022:1057-1 Security update for salt | почти 4 года назад | |||
SUSE-SU-2022:1051-1 Security update for salt | почти 4 года назад | |||
SUSE-RU-2022:1392-1 Recommended update for salt | почти 4 года назад | |||
SUSE-RU-2022:1391-1 Recommended update for salt | почти 4 года назад | |||
SUSE-RU-2022:1389-1 Recommended update for salt | почти 4 года назад | |||
SUSE-RU-2022:1385-1 Recommended update for Salt | почти 4 года назад | |||
SUSE-RU-2022:1384-1 Recommended update for Salt | почти 4 года назад |
Уязвимостей на страницу