{
  "threat_severity" : "Moderate",
  "public_date" : "2021-09-02T00:00:00Z",
  "bugzilla" : {
    "description" : "salt: allows malacious actor to subvert the proper behaviour of the given minion software",
    "id" : "2041836",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2041836"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-287",
  "details" : [ "An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\\salt\\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.", "An improper authentication flaw was found in SaltStack salt before version 3003.3. The Salt minion installer accepts and uses a minion config file at C:\\salt\\conf if that file is in place before the installer is run. This flaw allows a malicious actor to subvert the proper behavior of the given minion software." ],
  "package_state" : [ {
    "product_name" : "Red Hat Ceph Storage 2",
    "fix_state" : "Out of support scope",
    "package_name" : "salt",
    "cpe" : "cpe:/a:redhat:ceph_storage:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2021-22004\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-22004" ],
  "name" : "CVE-2021-22004",
  "csaw" : false
}