---
title: "CVE-2022-22941\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-22941?format=md
keywords: index, follow
---

# CVE-2022-22941

Publication date 29 March 2022

Last updated 26 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2022-22941?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in SaltStack Salt in versions before 3002.8,
3003.4, 3004.1. When configured as a Master-of-Masters, with a
publisher\_acl, if a user configured in the publisher\_acl targets any minion
connected to the Syndic, the Salt Master incorrectly interpreted no valid
targets as valid, allowing configured users to target any of the minions
connected to the syndic with their configured commands. This requires a
syndic master combined with publisher\_acl configured on the
Master-of-Masters, allowing users specified in the publisher\_acl to bypass
permissions, publishing authorized commands to any configured minion.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| salt | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Not in release |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Ignored end of life |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22941)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-22941)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-22941)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-22941)

### Other references

* <https://saltproject.io/security_announcements/salt-security-advisory-release/>
* <https://github.com/saltstack/salt/releases,>
* <https://repo.saltproject.io/>
* <https://saltproject.io/security_announcements/salt-security-advisory-release/,>
* <https://www.cve.org/CVERecord?id=CVE-2022-22941>
