CVE-2025-22237: Salt's on demand pillar functionality vulnerable to arbitrary command injections
An attacker with access to a minion key can exploit the ‘on demand’ pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-22237 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →