#VU111854 Improper Authorization in Salt - CVE-2025-22237

 

#VU111854 Improper Authorization in Salt - CVE-2025-22237

Published: June 23, 2025


Vulnerability identifier: #VU111854
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:U/U:Clear
CVE-ID: CVE-2025-22237
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Salt
Software vendor:
SaltStack

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper authorization. An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.


Remediation

Install updates from vendor's website.

External links