A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
CVSS Details
- CVSS 3.1 Base Score: 7.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Aug 22, 2024 | Jun 27, 2024 |
| Gentoo Linux | — | Upgrade app-admin/salt. | Dec 9, 2024 | Jun 27, 2024 |
| Suse | — | Upgrade salt-transactional-updateUpgrade salt-bash-completionUpgrade salt-cloudUpgrade salt-fish-completionUpgrade salt-zsh-completionUpgrade python3-saltUpgrade salt-proxyUpgrade saltUpgrade salt-sshUpgrade salt-apiUpgrade salt-syndicUpgrade salt-masterUpgrade salt-docUpgrade salt-standalone-formulas-configurationUpgrade salt-minion | Feb 16, 2024 | Feb 16, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub