CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2024-38824 CRITICAL

CVE-2024-38824 salt advisory

CVSS 9.6 EPSS 1.01% Jun 13, 2025
CVE-2023-20898 HIGH

Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that…

CVSS 7.8 EPSS 0.32% Sep 5, 2023
CVE-2023-20897 MEDIUM

Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker…

CVSS 5.3 EPSS 1.24% Sep 5, 2023
CVE-2021-33226 CRITICAL

Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py fil…

CVSS 9.8 EPSS 1.64% Feb 17, 2023
CVE-2022-22967 HIGH

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously author…

CVSS 7.7 EPSS 2.12% Jun 22, 2022
CVE-2022-22941 HIGH

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user co…

CVSS 8.8 EPSS 1.35% Mar 29, 2022
CVE-2022-22936 HIGH

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, w…

CVSS 8.8 EPSS 0.83% Mar 29, 2022
CVE-2022-22935 LOW

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to for…

CVSS 3.7 EPSS 1.62% Mar 29, 2022
CVE-2022-22934 HIGH

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which c…

CVSS 8.7 EPSS 0.88% Mar 29, 2022
CVE-2021-22004 HIGH

salt: allows malacious actor to subvert the proper behaviour of the given minion software

CVSS 7.5 EPSS 0.35% Sep 8, 2021
CVE-2021-21996 HIGH

salt: user having control of source and source_hash URLs leads to root access

CVSS 7.5 EPSS 3.51% Sep 8, 2021
CVE-2021-31607 HIGH

salt: Command injection in the snapper module

CVSS 7.8 EPSS 5.92% Apr 23, 2021
CVE-2021-25315 CRITICAL

salt-api unauthenticated remote code execution

CVSS 9.8 EPSS 2.33% Mar 3, 2021
CVE-2021-3197 CRITICAL

salt: Shell injection by including ProxyCommand in an argument

CVSS 9.8 EPSS 72.33% Feb 27, 2021
CVE-2021-3148 CRITICAL

salt: Command injection in salt.utils.thin.gen_thin()

CVSS 9.8 EPSS 8.25% Feb 27, 2021
CVE-2021-3144 CRITICAL

salt: eauth tokens can be used once after expiration

CVSS 9.1 EPSS 5.24% Feb 27, 2021
CVE-2021-25284 MEDIUM

salt: webutils write passwords in cleartext to /var/log/salt/minion

CVSS 4.4 EPSS 0.54% Feb 27, 2021
CVE-2021-25283 CRITICAL

salt: Jinja renderer does not protect against server-side template injection attacks

CVSS 9.8 EPSS 10.51% Feb 27, 2021
CVE-2021-25282 HIGH

salt: Directory traversal in wheel.pillar_roots.write

CVSS 8.8 EPSS 92.41% Feb 27, 2021
CVE-2021-25281 CRITICAL

salt: API does not honor eAuth credentials for the wheel_async client

CVSS 9.8 EPSS 73.13% Feb 27, 2021
CVE-2020-35662 HIGH

salt: Certain modules do not always validated SSL certificates

CVSS 7.4 EPSS 2.98% Feb 27, 2021
CVE-2020-28972 HIGH

salt: Authentication to vCenter, vSphere, and ESXi servers does not always validate the SSL/TLS certificate

CVSS 8.2 EPSS 3.09% Feb 27, 2021
CVE-2020-28243 HIGH

salt: Privilege escalation on a minion when an unprivileged user is able to create files in any non-blacklisted directory

CVSS 7.8 EPSS 4.30% Feb 27, 2021
CVE-2020-25592 CRITICAL

salt: salt-netapi improperly validates eauth credentials and tokens

CVSS 9.8 EPSS 57.73% Nov 6, 2020
CVE-2020-17490 MEDIUM

salt: creates certificates with weak file permissions

CVSS 5.5 EPSS 0.42% Nov 6, 2020

Showing 1 to 25 CVEs · page 1 (more available)