Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Salt HIGH 7.5
CVE-2024-38824

Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.

Fix: 3006.12 / 3007.4+
Fix from $1,950 2025-06-13
Salt HIGH 7.8
CVE-2023-20898

Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anyt…

Fix: 3005.2 / 3006.2+
Fix from $1,950 2023-09-05
Salt MEDIUM 5.3
CVE-2023-20897

Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number …

Fix: 3005.2 / 3006.2+
Fix from $1,600 2023-09-05
Salt CRITICAL 9.8
CVE-2021-33226

Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/sta…

Fix: after 3003
Fix from $2,300 2023-02-17
Salt HIGH 8.8
CVE-2022-22967

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previou…

Fix: 3002.9 / 3003.5+
Fix from $1,950 2022-06-23
Salt HIGH 8.8
CVE-2022-22934

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public ke…

Fix: 3002.8 / 3003.4+
Fix from $1,950 2022-03-29
Salt HIGH 8.8
CVE-2022-22936

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay …

Fix: 3002.8 / 3003.4+
Fix from $1,950 2022-03-29
Salt HIGH 8.8
CVE-2022-22941

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if…

Fix: 3002.8 / 3003.4+
Fix from $1,950 2022-03-29
Salt HIGH 7.8
CVE-2021-25315

CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute a…

Fix: 3002.2+
Fix from $1,950 2021-03-03
Saltstack HIGH 8.1
CVE-2013-2228

SaltStack RSA Key Generation allows remote users to decrypt communications

Fix: after 0.15.0
Fix from $1,950 2019-12-03
Salt 2018 CRITICAL 9.8
CVE-2019-1010259

SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud p…

Patch available
Fix from $2,300 2019-07-18
Salt CRITICAL 9.8
CVE-2018-15751EPSS 5%

SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-a…

Fix: 2017.7.8 / 2018.3.3+
Fix from $2,300 2018-10-24
Salt MEDIUM 5.3
CVE-2018-15750

Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine whi…

Fix: 2017.7.8 / 2018.3.3+
Fix from $1,600 2018-10-24
Salt CRITICAL 9.8
CVE-2017-7893

In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.

Fix: 2016.3.6+
Fix from $2,300 2018-04-23
Salt CRITICAL 9.8
CVE-2017-14695

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2…

Fix: after 2016.3.7
Fix from $2,300 2017-10-24
Salt HIGH 7.5
CVE-2017-14696

SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a c…

Fix: after 2016.3.7
Fix from $1,950 2017-10-24
Salt 2015 MEDIUM 6.3
CVE-2015-6918

salt before 2015.5.5 leaks git usernames and passwords to the log.

Fix: after 5.4
Fix from $1,600 2017-10-10
Salt HIGH 8.8
CVE-2017-5192

When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, externa…

Fix: after 2015.8.12
Fix from $1,950 2017-09-26
Salt HIGH 8.8
CVE-2017-5200

Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-ma…

Fix: after 2015.8.12
Fix from $1,950 2017-09-26
Salt HIGH 7.5
CVE-2015-4017

Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.

Patch available
Fix from $1,950 2017-08-25
Salt CRITICAL 9.8
CVE-2017-12791

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with …

Fix: after 2016.11.6
Fix from $2,300 2017-08-23
Salt 2015 CRITICAL 9.8
CVE-2015-6941

win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.

Patch available
Fix from $2,300 2017-08-09
Salt HIGH 7.8
CVE-2017-8109

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, whi…

Patch available
Fix from $1,950 2017-04-25
Salt CRITICAL 9.1
CVE-2016-9639

Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.

Fix: after 2015.8.10
Fix from $2,300 2017-02-07
Salt MEDIUM 5.6
CVE-2016-3176

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentica…

Fix: after 2015.5.9
Fix from $1,600 2017-01-31
Salt HIGH 8.1
CVE-2016-1866

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2016-04-12
Salt HIGH 7.2
CVE-2014-3563

Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to …

Fix: after 2014.1.9
Fix from $1,950 2014-08-22
Salt HIGH 10.0
CVE-2013-6617

The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to …

Mitigation only
Fix from $1,950 2013-11-05
Salt HIGH 10.0
CVE-2013-4437

Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."

Patch available
Fix from $1,950 2013-11-05
Salt HIGH 9.3
CVE-2013-4436

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers t…

Patch available
Fix from $1,950 2013-11-05