Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 PyPI

Salt has minion event bus authorization bypass vulnerability

GHSA-jh7c-xh74-h76f · CVE-2025-22236

Published · Modified

Description

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

Ready to move

Start Securing

Free, no credit card | First findings in minutes