PT-2025-25391 · Saltstack+3 · Saltstack Salt+3

CVE-2025-22236

·

Published

2025-01-02

·

Updated

2026-07-07

CVSS v3.1

8.1

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions SaltStack Salt versions 3007.0 and later
Description The issue concerns an authorization bypass in the Minion event bus. An attacker with access to a minion key can craft a message to potentially execute a job on other minions.
Recommendations For versions 3007.0 and later, update to a version that includes a fix for the authorization bypass issue in the Minion event bus.

Fix

Improper Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8072
ALT-PU-2025-8965
BDU:2025-10868
CVE-2025-22236
GHSA-JH7C-XH74-H76F
OPENSUSE-SU-2025:15295-1
PYSEC-2026-1899
SUSE-EL-9-CLIENT-TOOLS-2025-2499
SUSE-SU-2025:02476-1
SUSE-SU-2025:02491-1
SUSE-SU-2025:02492-1
SUSE-SU-2025:02499-1
SUSE-SU-2025:02500-1
SUSE-SU-2025:02501-1
SUSE-SU-2025:02502-1
SUSE-SU-2025:02534-1
SUSE-SU-2025:20487-1
SUSE-SU-2025:20504-1
SUSE-SU-2025_02500-1
SUSE-SU-2025_02501-1
SUSE-SU-2025_02534-1

Affected Products

Alt Linux
Red Os
Saltstack Salt
Suse