Search CVE reports


Toggle filters

11 – 20 of 75 results


CVE-2025-22237

Medium priority
Vulnerable

An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Needs evaluation
Show less packages

CVE-2025-22236

Medium priority
Vulnerable

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Needs evaluation
Show less packages

CVE-2024-38825

Medium priority
Vulnerable

The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not...

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Needs evaluation
Show less packages

CVE-2024-38823

Medium priority
Vulnerable

Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Needs evaluation
Show less packages

CVE-2024-38822

Medium priority
Vulnerable

Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Needs evaluation
Show less packages

CVE-2023-34049

Medium priority
Vulnerable

The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight...

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Not in release Needs evaluation
Show less packages

CVE-2024-22232

Medium priority
Vulnerable

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Not in release Vulnerable
Show less packages

CVE-2024-22231

Medium priority
Vulnerable

Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Not in release Vulnerable
Show less packages

CVE-2023-20898

Medium priority
Vulnerable

Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that uses Git Providers with different environments can get garbage data or...

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Not in release Vulnerable
Show less packages

CVE-2023-20897

Medium priority
Vulnerable

Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.

1 affected package

salt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
salt Not in release Not in release Vulnerable Not in release Needs evaluation
Show less packages