Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-38824 Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory. Salt 3006.12 / 3007.4+ Fix from $1,9502025-06-13 HIGH 7.8 CVE-2023-20898 Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anyt… Salt 3005.2 / 3006.2+ Fix from $1,9502023-09-05 MEDIUM 5.3 CVE-2023-20897 Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number … Salt 3005.2 / 3006.2+ Fix from $1,6002023-09-05 CRITICAL 9.8 CVE-2021-33226 Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/sta… Salt after 3003 Fix from $2,3002023-02-17 HIGH 8.8 CVE-2022-22967 An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previou… Salt 3002.9 / 3003.5+ Fix from $1,9502022-06-23 HIGH 8.8 CVE-2022-22934 An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public ke… Salt 3002.8 / 3003.4+ Fix from $1,9502022-03-29 HIGH 8.8 CVE-2022-22936 An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay … Salt 3002.8 / 3003.4+ Fix from $1,9502022-03-29 HIGH 8.8 CVE-2022-22941 An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if… Salt 3002.8 / 3003.4+ Fix from $1,9502022-03-29 HIGH 7.8 CVE-2021-25315 CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute a… Salt 3002.2+ Fix from $1,9502021-03-03 HIGH 8.1 CVE-2013-2228 SaltStack RSA Key Generation allows remote users to decrypt communications Saltstack after 0.15.0 Fix from $1,9502019-12-03 CRITICAL 9.8 CVE-2019-1010259 SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud p… Salt 2018 Patch available Fix from $2,3002019-07-18 CRITICAL 9.8 CVE-2018-15751EPSS 5% SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-a… Salt 2017.7.8 / 2018.3.3+ Fix from $2,3002018-10-24 MEDIUM 5.3 CVE-2018-15750 Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine whi… Salt 2017.7.8 / 2018.3.3+ Fix from $1,6002018-10-24 CRITICAL 9.8 CVE-2017-7893 In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master. Salt 2016.3.6+ Fix from $2,3002018-04-23 CRITICAL 9.8 CVE-2017-14695 Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2… Salt after 2016.3.7 Fix from $2,3002017-10-24 HIGH 7.5 CVE-2017-14696 SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a c… Salt after 2016.3.7 Fix from $1,9502017-10-24 MEDIUM 6.3 CVE-2015-6918 salt before 2015.5.5 leaks git usernames and passwords to the log. Salt 2015 after 5.4 Fix from $1,6002017-10-10 HIGH 8.8 CVE-2017-5192 When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, externa… Salt after 2015.8.12 Fix from $1,9502017-09-26 HIGH 8.8 CVE-2017-5200 Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-ma… Salt after 2015.8.12 Fix from $1,9502017-09-26 HIGH 7.5 CVE-2015-4017 Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules. Salt Patch available Fix from $1,9502017-08-25 CRITICAL 9.8 CVE-2017-12791 Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with … Salt after 2016.11.6 Fix from $2,3002017-08-23 CRITICAL 9.8 CVE-2015-6941 win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs. Salt 2015 Patch available Fix from $2,3002017-08-09 HIGH 7.8 CVE-2017-8109 The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, whi… Salt Patch available Fix from $1,9502017-04-25 CRITICAL 9.1 CVE-2016-9639 Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching. Salt after 2015.8.10 Fix from $2,3002017-02-07 MEDIUM 5.6 CVE-2016-3176 Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentica… Salt after 2015.5.9 Fix from $1,6002017-01-31 HIGH 8.1 CVE-2016-1866 Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary co… Salt Mitigation only Fix from $1,9502016-04-12 HIGH 7.2 CVE-2014-3563 Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to … Salt after 2014.1.9 Fix from $1,9502014-08-22 HIGH 10.0 CVE-2013-6617 The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to … Salt Mitigation only Fix from $1,9502013-11-05 HIGH 10.0 CVE-2013-4437 Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp." Salt Patch available Fix from $1,9502013-11-05 HIGH 9.3 CVE-2013-4436 The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers t… Salt Patch available Fix from $1,9502013-11-05