Alpine: multiple salt packages: security update to 3004.1-r0

high Tenable Cloud Security Plugin ID 407047

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not
sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar
data. (CVE-2022-22934)

- An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion
authentication denial of service can cause a MiTM attacker to force a minion process to stop by
impersonating a master. (CVE-2022-22935)

- An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and
file server replies are susceptible to replay attacks, which can result in an attacker replaying job
publishes causing minions to run old jobs. File server replies can also be re-played. A sufficient craft
attacker could gain root access on minion under certain scenarios. (CVE-2022-22936)

- An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a
Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion
connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing
configured users to target any of the minions connected to the syndic with their configured commands. This
requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users
specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured
minion. (CVE-2022-22941)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-22934

https://security.alpinelinux.org/vuln/CVE-2022-22935

https://security.alpinelinux.org/vuln/CVE-2022-22936

https://security.alpinelinux.org/vuln/CVE-2022-22941

Plugin Details

Severity: High

ID: 407047

Version: Revision 1.33

Type: Local

Published: 10/31/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.4

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2022-22941

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2022-22934

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 3/29/2022

Reference Information

CVE: CVE-2022-22934, CVE-2022-22935, CVE-2022-22936, CVE-2022-22941

IAVA: 2022-A-0128-S