CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
CVE-2024-38824 salt advisory
Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that…
Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker…
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py fil…
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously author…
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user co…
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, w…
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to for…
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which c…
salt: allows malacious actor to subvert the proper behaviour of the given minion software
salt: user having control of source and source_hash URLs leads to root access
salt: Command injection in the snapper module
salt-api unauthenticated remote code execution
salt: Shell injection by including ProxyCommand in an argument
salt: Command injection in salt.utils.thin.gen_thin()
salt: eauth tokens can be used once after expiration
salt: webutils write passwords in cleartext to /var/log/salt/minion
salt: Jinja renderer does not protect against server-side template injection attacks
salt: Directory traversal in wheel.pillar_roots.write
salt: API does not honor eAuth credentials for the wheel_async client
salt: Certain modules do not always validated SSL certificates
salt: Authentication to vCenter, vSphere, and ESXi servers does not always validate the SSL/TLS certificate
salt: Privilege escalation on a minion when an unprivileged user is able to create files in any non-blacklisted directory
salt: salt-netapi improperly validates eauth credentials and tokens
salt: creates certificates with weak file permissions
Showing 1 to 25 CVEs · page 1 (more available)