{"schema_version":"1.9.0","id":"CVE-2022-22934","published":"2022-03-29T00:00:00Z","modified":"2026-08-12T03:51:39.078384032Z","aliases":["GHSA-2q4g-wfm6-5fpm","PYSEC-2022-171"],"related":["SUSE-FU-2022:2042-1","SUSE-FU-2022:2135-1","SUSE-RU-2022:1384-1","SUSE-RU-2022:1385-1","SUSE-RU-2022:1389-1","SUSE-RU-2022:1391-1","SUSE-RU-2022:1392-1","SUSE-SU-2022:1049-1","SUSE-SU-2022:1050-1","SUSE-SU-2022:1051-1","SUSE-SU-2022:1057-1","SUSE-SU-2022:1058-1","SUSE-SU-2022:1059-1","SUSE-SU-2022:1060-1","SUSE-SU-2022:1514-1","SUSE-SU-2022:1531-1","SUSE-SU-2022:1536-1","SUSE-SU-2022:1545-1","openSUSE-SU-2022:1059-1","openSUSE-SU-2024:11970-1"],"details":"An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/saltstack/salt","events":[{"introduced":"998c382f5f2c3b4cbf7d96aa6913ada6993909b3"},{"fixed":"836789a88156bb19fdac3fa00139cd278f92418c"},{"introduced":"6fa95b058b9d999c23dff5eb2ba4127aa2dc8b71"},{"fixed":"99d30f4022cff1582bba0c28fd606897aa8d248a"},{"introduced":"fec6e71228f67d1d7bbf1abe32f98acb392d3697"},{"fixed":"064729c1ed085466cf4863403100461fbe4abd81"}],"database_specific":{"cpe":"cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3002"},{"fixed":"3002.8"},{"introduced":"3003"},{"fixed":"3003.4"},{"introduced":"3004"},{"fixed":"3004.1"}],"source":"CPE_RANGE"}}],"versions":["v3004","v3004rc1","v3002.7","v3003.3","v3002.6","v3003.2","v3003.1","v3003_docs","v3003rc1","v3002.5","v3002.4","v3002.3","v3002.2","v3002"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22934.json"}}],"references":[{"type":"WEB","url":"https://github.com/saltstack/salt/releases%2C"},{"type":"WEB","url":"https://repo.saltproject.io/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/22xxx/CVE-2022-22934.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-22934"},{"type":"ADVISORY","url":"https://saltproject.io/security_announcements/salt-security-advisory-release/%2C"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202310-22"}],"database_specific":{"cna_assigner":"vmware","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/22xxx/CVE-2022-22934.json","unresolved_ranges":[{"extracted_events":[{"introduced":"SaltStack Salt prior to 3002.8, 3003.4, 3004.1"},{"last_affected":"SaltStack Salt prior to 3002.8, 3003.4, 3004.1"}],"source":"AFFECTED_FIELD"}]}}