File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “authorization file” at a specific location and is present in the default configuration.
CVSS Details
- CVSS 3.1 Base Score: 5.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade salt-masterUpgrade salt-zsh-completionUpgrade salt-cloudUpgrade salt-syndicUpgrade python3-saltUpgrade salt-minionUpgrade salt-sshUpgrade salt-fish-completionUpgrade salt-bash-completionUpgrade salt-proxyUpgrade salt-transactional-updateUpgrade python3-salt-testsuiteUpgrade salt-docUpgrade salt-standalone-formulas-configurationUpgrade salt-apiUpgrade salt | Dec 5, 2025 | Jul 23, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub