A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
CVSS Details
- CVSS 3.1 Base Score: 7.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade salt | Aug 22, 2024 | Jun 27, 2024 |
| Gentoo Linux | — | Upgrade app-admin/salt. | Dec 9, 2024 | Jun 27, 2024 |
| Suse | — | Upgrade salt-transactional-updateUpgrade salt-fish-completionUpgrade python3-saltUpgrade salt-zsh-completionUpgrade salt-cloudUpgrade salt-bash-completionUpgrade salt-syndicUpgrade salt-standalone-formulas-configurationUpgrade salt-proxyUpgrade salt-sshUpgrade salt-docUpgrade salt-masterUpgrade saltUpgrade salt-apiUpgrade salt-minion | Feb 16, 2024 | Feb 16, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub