CVE-2022-22941: SaltStack Salt

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.

Affected products

  • SaltStack Salt: from 3002, before 3002.8 (fixed in 3002.8); from 3003, before 3003.4 (fixed in 3003.4); from 3004, before 3004.1 (fixed in 3004.1)

Published 2022-03-29. Last modified 2026-06-17.