CVE-2025-22241

File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “authorization file” at a specific location and is present in the default configuration.
Configurations

No configuration.

History

17 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-13 07:15

Updated : 2025-06-17 18:15


NVD link : CVE-2025-22241

Mitre link : CVE-2025-22241

CVE.ORG link : CVE-2025-22241


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')