Path Traversal Vulnerability in SaltStack Configuration Management
CVE-2025-22241
What is CVE-2025-22241?
A path traversal vulnerability in SaltStack Configuration Management allows attackers to exploit unvalidated input in the VirtKey class. This issue arises during the processing of 'on-demand pillar' data requests, which can lead to the creation of arbitrary file paths pointing to the 'pki directory'. The inherent functionality enables automatic acceptance of Minion authentication keys through a pre-existing 'authorization file' located in the default configuration. As such, unauthorized users could potentially overwrite critical system files, jeopardizing the integrity of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SALT 3006.x < 3006.12
SALT 3007.x < 3007.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved