Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade salt-fish-completionUpgrade salt-cloudUpgrade salt-standalone-formulas-configurationUpgrade python3-saltUpgrade python3-salt-testsuiteUpgrade salt-zsh-completionUpgrade salt-apiUpgrade salt-transactional-updateUpgrade salt-bash-completionUpgrade saltUpgrade salt-syndicUpgrade salt-docUpgrade salt-masterUpgrade salt-sshUpgrade salt-minionUpgrade salt-proxy | Dec 5, 2025 | Jul 23, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub