4.4
CVSSv2

CVE-2021-22004

Published: 08/09/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.4 | Impact Score: 5.9 | Exploitability Score: 0.5
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in SaltStack Salt prior to 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Debian Bug report logs - #994016 salt: CVE-2021-21996 CVE-2021-22004 Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 9 Sep 2021 19:33:02 UTC Severity: grave Tags: security, upstream Found in vers ...
An issue was discovered in SaltStack Salt before 30033 The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run This allows for a malicious actor to subvert the proper behaviour of the given minion software ...