Arbitrary Event Injection Vulnerability in Salt Master by SaltStack
CVE-2025-22239
8.1HIGH
What is CVE-2025-22239?
A vulnerability exists in Salt Master, allowing an authorized minion to exploit the master's '_minion_event' method. This could enable threatened actors to send arbitrary events to the master's event bus, potentially impacting the integrity and security of the connected network. Users are advised to evaluate their use of affected versions and apply the appropriate patches or upgrades.
Affected Version(s)
SALT 3006.x < 3006.12
SALT 3007.x < 3007.4