An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade salt-apiUpgrade salt-cloudUpgrade salt-bash-completionUpgrade python3-salt-testsuiteUpgrade salt-masterUpgrade salt-docUpgrade salt-transactional-updateUpgrade salt-minionUpgrade saltUpgrade salt-proxyUpgrade salt-standalone-formulas-configurationUpgrade salt-sshUpgrade salt-zsh-completionUpgrade python3-saltUpgrade salt-syndicUpgrade salt-fish-completion | Dec 5, 2025 | Jul 23, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub