CVE-2024-38822
Awaiting Analysis
Awaiting Analysis - Queue
BaseFortify
Publication date: 2025-06-13
Last updated on: 2025-06-16
Assigner: VMware
Description
Description
Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves multiple methods in the salt master that skip minion token validation, allowing a misbehaving minion to impersonate another minion.
How can this vulnerability impact me? :
The vulnerability allows a misbehaving minion to impersonate another minion, which could lead to unauthorized actions or interference within the salt master environment, potentially impacting system integrity.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70