CVE-2025-22241 - CERT CVE
ID CVE-2025-22241
Sažetak File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “authorization file” at a specific location and is present in the default configuration.
Reference
CVSS
Base: 5.6
Impact: 5.2
Exploitability:0.3
Pristup
VektorSloženostAutentikacija
LOCAL HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH NONE
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Zadnje važnije ažuriranje 17-06-2025 - 18:15
Objavljeno 13-06-2025 - 07:15