An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/saltstack/salt/releases%2C | Broken Link | 
| https://repo.saltproject.io/ | Product | 
| https://saltproject.io/security_announcements/salt-security-advisory-release/%2C | Broken Link | 
| https://security.gentoo.org/glsa/202310-22 | Third Party Advisory | 
| https://github.com/saltstack/salt/releases%2C | Broken Link | 
| https://repo.saltproject.io/ | Product | 
| https://saltproject.io/security_announcements/salt-security-advisory-release/%2C | Broken Link | 
| https://security.gentoo.org/glsa/202310-22 | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 06:47
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/saltstack/salt/releases%2C - Broken Link | |
| References | () https://repo.saltproject.io/ - Product | |
| References | () https://saltproject.io/security_announcements/salt-security-advisory-release/%2C - Broken Link | |
| References | () https://security.gentoo.org/glsa/202310-22 - Third Party Advisory | 
21 Dec 2023, 18:44
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (GENTOO) https://security.gentoo.org/glsa/202310-22 - Third Party Advisory | |
| References | () https://saltproject.io/security_announcements/salt-security-advisory-release/%2C - Broken Link | |
| References | () https://github.com/saltstack/salt/releases%2C - Broken Link | 
07 Nov 2023, 03:44
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
 | 
31 Oct 2023, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
Information
                Published : 2022-03-29 17:15
Updated : 2025-05-05 17:17
NVD link : CVE-2022-22941
Mitre link : CVE-2022-22941
CVE.ORG link : CVE-2022-22941
JSON object : View
Products Affected
                saltstack
- salt
CWE
                
                    
                        
                        CWE-732
                        
            Incorrect Permission Assignment for Critical Resource
