CVE-2021-22004

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-09-08 15:15

Updated : 2023-11-07 03:30


NVD link : CVE-2021-22004

Mitre link : CVE-2021-22004

CVE.ORG link : CVE-2021-22004


JSON object : View

Products Affected

fedoraproject

  • fedora

saltstack

  • salt

microsoft

  • windows
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')