Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-22241


File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “authorization file” at a specific location and is present in the default configuration.


Published

2025-06-13T07:15:21.567

Last Modified

2025-06-17T18:15:25.043

Status

Awaiting Analysis

Source

[email protected]

Severity

CVSSv3.1: 5.6 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products

-


References