Search CVE reports
1 – 10 of 59 results
CVE-2023-34049
Medium priorityThe Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight...
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-22232
Medium priorityA specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | Not in release | Needs evaluation | Needs evaluation |
CVE-2024-22231
Medium prioritySyndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-20898
Medium priorityGit Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that uses Git Providers with different environments can get garbage data or...
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-20897
Medium prioritySalt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | Not in release | Needs evaluation | Needs evaluation |
CVE-2023-28370
Medium prioritySome fixes available 5 of 11
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
2 affected packages
python-tornado, salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-tornado | Not affected | Fixed | Fixed | Fixed | Fixed |
salt | Not in release | Needs evaluation | Not in release | Needs evaluation | Needs evaluation |
CVE-2022-22967
Medium priorityAn issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their...
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | — | Needs evaluation | Needs evaluation |
CVE-2022-22941
Low priorityAn issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the...
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | — | Needs evaluation | Needs evaluation |
CVE-2022-22936
Medium priorityAn issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions...
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | — | Needs evaluation | Needs evaluation |
CVE-2022-22935
Low priorityAn issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
1 affected package
salt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
salt | Not in release | Needs evaluation | — | Needs evaluation | Needs evaluation |