Authentication Flaw in Salt Project's PKI Module Affects Multiple Versions
CVE-2024-38825
6.4MEDIUM
What is CVE-2024-38825?
The salt.auth.pki module contains an authentication flaw that allows unauthorized access. In this module, the 'password' field is expected to contain a public certificate, which is incorrectly validated against a Certificate Authority (CA) certificate. Consequently, the authentication process does not require the caller to possess the corresponding private key, thereby circumventing proper PKI authentication measures. This vulnerability could potentially allow malicious actors to bypass security protocols and execute unauthorized actions within the affected systems.
Affected Version(s)
SALT 3006.x < 3006.12
SALT 3007.x < 3007.4