An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.
                
            References
                    Configurations
                    No configuration.
History
                    13 Jun 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-77 | |
| Summary | 
        
        
  | 
13 Jun 2025, 07:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-13 07:15
Updated : 2025-06-16 12:32
NVD link : CVE-2025-22237
Mitre link : CVE-2025-22237
CVE.ORG link : CVE-2025-22237
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
