Access Restriction Bypass Affecting salt package, versions [,3002.9) [3003,3003.5) [3004,3004.2)
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-SALT-2934958
- published 23 Jun 2022
- disclosed 23 Jun 2022
- credit ysf
Introduced: 23 Jun 2022
CVE-2022-22967 Open this link in a new tabHow to fix?
Upgrade salt
to version 3002.9, 3003.5, 3004.2 or higher.
Overview
salt is a new approach to infrastructure management built on a dynamic communication bus. Salt can be used for data-driven orchestration, remote execution for any infrastructure, configuration management for any app stack, and much more.
Affected versions of this package are vulnerable to Access Restriction Bypass where a previously authorized user whose account is locked can still run Salt commands. This affects both local shell accounts with an active session and salt-api
users that authenticate via PAM
eauth
.
Workaround: If the user can not upgrade to the fixed version, it is possible to:
remove locked accounts rather than rely on Salt’s PAM
eauth
functionality.change to a different
eauth
module.