Permissions, Privileges, and Access Controls in Salt - CVE-2025-22241

 

Permissions, Privileges, and Access Controls in Salt - CVE-2025-22241

Published: June 23, 2025


Vulnerability identifier: #VU111858
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22241
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “authorization file” at a specific location and is present in the default configuration.


Affected software

Salt
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Fedora
SUSE Multi-Linux Manager Client Tools for Debian
openSUSE Leap
SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04
SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04
spacecmd
mgrctl
mgrctl-zsh-completion
mgrctl-bash-completion
mgrctl-fish-completion
venv-salt-minion
salt-bash-completion
salt-fish-completion
salt-minion
salt
python3-salt-testsuite
python3-salt
salt-proxy
salt-cloud
salt-syndic
salt-doc
salt-transactional-update
salt-api
salt-master
salt-ssh
salt-standalone-formulas-configuration
salt-zsh-completion
salt3006
Session Smart Router

How to mitigate CVE-2025-22241

Install updates from vendor's website.

Salt - update to 3007.4
spacecmd - addressed in versions 5.1.8-3.6.1, 5.1.8-3.8.1, 5.1.10-3.11.1
mgrctl - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-zsh-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-bash-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-fish-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
venv-salt-minion - addressed in versions 3006.0-3.6.2, 3006.0-3.6.3, 3006.0-3.8.4
salt-bash-completion - update to 3006.0-150300.53.94.1
salt-fish-completion - update to 3006.0-150300.53.94.1
salt-minion - update to 3006.0-150300.53.94.1
salt - update to 3006.0-150300.53.94.1
python3-salt-testsuite - update to 3006.0-150300.53.94.1
python3-salt - update to 3006.0-150300.53.94.1
salt-proxy - update to 3006.0-150300.53.94.1
salt-cloud - update to 3006.0-150300.53.94.1
salt-syndic - update to 3006.0-150300.53.94.1
salt-doc - update to 3006.0-150300.53.94.1
salt-transactional-update - update to 3006.0-150300.53.94.1
salt-api - update to 3006.0-150300.53.94.1
salt-master - update to 3006.0-150300.53.94.1
salt-ssh - update to 3006.0-150300.53.94.1
salt-standalone-formulas-configuration - update to 3006.0-150300.53.94.1
salt-zsh-completion - update to 3006.0-150300.53.94.1
salt3006 - update to 3006.12-1.el9
salt - addressed in versions 3007.4-2.fc43, 3007.4-3.fc42, 3007.4-4.fc41, 3007.4-4.fc42

External References

Related Security Bulletins