Medium severity6.4NVD Advisory· Published Sep 8, 2021· Updated Jun 17, 2026
CVE-2021-22004
CVE-2021-22004
Description
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
saltPyPI | < 3003.3 | 3003.3 |
Affected products
6- SaltStack/Saltdescription
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
11- saltproject.io/security_announcements/salt-security-advisory-2021-sep-02/nvdPatchVendor Advisory
- github.com/advisories/GHSA-xf37-qcvf-7m57ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-22004ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2021-346.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/6BUWUF5VTENNP2ZYZBVFKPSUHLKLUBD5ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ACVT7M4YLZRLWWQ6SGRK3C6TOF4FXOXTghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/MBAHHSGZLEJRCG4DX6J4RBWJAAWH55RQghsaWEB
- saltproject.io/security_announcements/salt-security-advisory-2021-sep-02ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6BUWUF5VTENNP2ZYZBVFKPSUHLKLUBD5/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ACVT7M4YLZRLWWQ6SGRK3C6TOF4FXOXT/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MBAHHSGZLEJRCG4DX6J4RBWJAAWH55RQ/nvd
News mentions
0No linked articles in our index yet.