Improper Authorization in Salt - CVE-2025-22237

 

Improper Authorization in Salt - CVE-2025-22237

Published: June 23, 2025


Vulnerability identifier: #VU111854
CSH Severity: Low
CVSS v4: 6.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2025-22237
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper authorization. An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.


Affected software

Salt
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Fedora
SUSE Multi-Linux Manager Client Tools for Debian
openSUSE Leap
SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04
SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04
spacecmd
mgrctl
mgrctl-zsh-completion
mgrctl-bash-completion
mgrctl-fish-completion
venv-salt-minion
salt-zsh-completion
salt-minion
salt
python3-salt-testsuite
python3-salt
salt-proxy
salt-cloud
salt-syndic
salt-doc
salt-transactional-update
salt-api
salt-master
salt-ssh
salt-bash-completion
salt-fish-completion
salt-standalone-formulas-configuration
salt3006
Session Smart Router

How to mitigate CVE-2025-22237

Install updates from vendor's website.

Salt - update to 3007.4
spacecmd - addressed in versions 5.1.8-3.6.1, 5.1.8-3.8.1, 5.1.10-3.11.1
mgrctl - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-zsh-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-bash-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-fish-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
venv-salt-minion - addressed in versions 3006.0-3.6.2, 3006.0-3.6.3, 3006.0-3.8.4
salt-zsh-completion - update to 3006.0-150300.53.94.1
salt-minion - update to 3006.0-150300.53.94.1
salt - update to 3006.0-150300.53.94.1
python3-salt-testsuite - update to 3006.0-150300.53.94.1
python3-salt - update to 3006.0-150300.53.94.1
salt-proxy - update to 3006.0-150300.53.94.1
salt-cloud - update to 3006.0-150300.53.94.1
salt-syndic - update to 3006.0-150300.53.94.1
salt-doc - update to 3006.0-150300.53.94.1
salt-transactional-update - update to 3006.0-150300.53.94.1
salt-api - update to 3006.0-150300.53.94.1
salt-master - update to 3006.0-150300.53.94.1
salt-ssh - update to 3006.0-150300.53.94.1
salt-bash-completion - update to 3006.0-150300.53.94.1
salt-fish-completion - update to 3006.0-150300.53.94.1
salt-standalone-formulas-configuration - update to 3006.0-150300.53.94.1
salt3006 - update to 3006.12-1.el9
salt - addressed in versions 3007.4-3.fc42, 3007.4-4.fc41, 3007.4-4.fc42

External References

Related Security Bulletins