CVE-2025-22237

An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.
Configurations

No configuration.

History

13 Jun 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) Un atacante con acceso a una clave de subordinado puede explotar la funcionalidad del pilar "a pedido" con una URL git especialmente manipulada que podrĂ­a hacer que se ejecute un comando arbitrario en el maestro con los mismos privilegios que el proceso maestro.
CWE CWE-77

13 Jun 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-13 07:15

Updated : 2025-06-13 14:15


NVD link : CVE-2025-22237

Mitre link : CVE-2025-22237

CVE.ORG link : CVE-2025-22237


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')