Permissions, Privileges, and Access Controls in Salt - CVE-2025-22240

 

Permissions, Privileges, and Access Controls in Salt - CVE-2025-22240

Published: June 23, 2025


Vulnerability identifier: #VU111857
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22240
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to manipulate with files and directories.

The vulnerability exists due to improper input validation in find_file method of the GitFS class. A local user can create arbitrary directories or delete any file on the Master's process without necessary permissions. 


Affected software

Salt
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Fedora
SUSE Multi-Linux Manager Client Tools for Debian
openSUSE Leap
SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04
SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04
spacecmd
mgrctl
mgrctl-zsh-completion
mgrctl-bash-completion
mgrctl-fish-completion
venv-salt-minion
salt-bash-completion
salt-fish-completion
salt-minion
salt
python3-salt-testsuite
python3-salt
salt-proxy
salt-cloud
salt-syndic
salt-doc
salt-transactional-update
salt-api
salt-master
salt-ssh
salt-standalone-formulas-configuration
salt-zsh-completion
salt3006
Session Smart Router

How to mitigate CVE-2025-22240

Install updates from vendor's website.

Salt - update to 3007.4
spacecmd - addressed in versions 5.1.8-3.6.1, 5.1.8-3.8.1, 5.1.10-3.11.1
mgrctl - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-zsh-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-bash-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-fish-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
venv-salt-minion - addressed in versions 3006.0-3.6.2, 3006.0-3.6.3, 3006.0-3.8.4
salt-bash-completion - update to 3006.0-150300.53.94.1
salt-fish-completion - update to 3006.0-150300.53.94.1
salt-minion - update to 3006.0-150300.53.94.1
salt - update to 3006.0-150300.53.94.1
python3-salt-testsuite - update to 3006.0-150300.53.94.1
python3-salt - update to 3006.0-150300.53.94.1
salt-proxy - update to 3006.0-150300.53.94.1
salt-cloud - update to 3006.0-150300.53.94.1
salt-syndic - update to 3006.0-150300.53.94.1
salt-doc - update to 3006.0-150300.53.94.1
salt-transactional-update - update to 3006.0-150300.53.94.1
salt-api - update to 3006.0-150300.53.94.1
salt-master - update to 3006.0-150300.53.94.1
salt-ssh - update to 3006.0-150300.53.94.1
salt-standalone-formulas-configuration - update to 3006.0-150300.53.94.1
salt-zsh-completion - update to 3006.0-150300.53.94.1
salt3006 - update to 3006.12-1.el9
salt - addressed in versions 3007.4-2.fc43, 3007.4-3.fc42, 3007.4-4.fc41, 3007.4-4.fc42

External References

Related Security Bulletins