Salt

Saltstack · 52 CVEs

CVE-2024-38824
CRITICAL

CVE-2024-38824 salt advisory

Jun 13, 2025

CVE-2023-20898
HIGH

Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters p…

Sep 5, 2023

CVE-2023-20897
MEDIUM

Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the reque…

Sep 5, 2023

CVE-2021-33226
CRITICAL

Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func var…

Feb 17, 2023

CVE-2022-22967
HIGH

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked ac…

Jun 22, 2022

CVE-2022-22941
HIGH

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Mas…

Mar 29, 2022

CVE-2022-22936
HIGH

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server repl…

Mar 29, 2022

CVE-2022-22935
LOW

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of…

Mar 29, 2022

CVE-2022-22934
HIGH

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar da…

Mar 29, 2022

CVE-2021-22004
HIGH

salt: allows malacious actor to subvert the proper behaviour of the given minion software

Sep 8, 2021

CVE-2021-21996
HIGH

salt: user having control of source and source_hash URLs leads to root access

Sep 8, 2021

CVE-2021-31607
HIGH

salt: Command injection in the snapper module

Apr 23, 2021

CVE-2021-25315
CRITICAL

salt-api unauthenticated remote code execution

Mar 3, 2021

CVE-2021-3197
CRITICAL

salt: Shell injection by including ProxyCommand in an argument

Feb 27, 2021

CVE-2021-3148
CRITICAL

salt: Command injection in salt.utils.thin.gen_thin()

Feb 27, 2021

CVE-2021-3144
CRITICAL

salt: eauth tokens can be used once after expiration

Feb 27, 2021

CVE-2021-25284
MEDIUM

salt: webutils write passwords in cleartext to /var/log/salt/minion

Feb 27, 2021

CVE-2021-25283
CRITICAL

salt: Jinja renderer does not protect against server-side template injection attacks

Feb 27, 2021

CVE-2021-25282
HIGH

salt: Directory traversal in wheel.pillar_roots.write

Feb 27, 2021

CVE-2021-25281
CRITICAL

salt: API does not honor eAuth credentials for the wheel_async client

Feb 27, 2021

CVE-2020-35662
HIGH

salt: Certain modules do not always validated SSL certificates

Feb 27, 2021

CVE-2020-28972
HIGH

salt: Authentication to vCenter, vSphere, and ESXi servers does not always validate the SSL/TLS certificate

Feb 27, 2021

CVE-2020-28243
HIGH

salt: Privilege escalation on a minion when an unprivileged user is able to create files in any non-blacklisted directo…

Feb 27, 2021

CVE-2020-25592
CRITICAL

salt: salt-netapi improperly validates eauth credentials and tokens

Nov 6, 2020

CVE-2020-17490
MEDIUM

salt: creates certificates with weak file permissions

Nov 6, 2020

Showing 1 to 25 of 52 CVEs