Saltstack / Salt
52 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-38824 | CVE-2024-38824 salt advisory | CRITICAL | 9.6 | Jun 13, 2025 |
| CVE-2023-20898 | Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that… | HIGH | 7.8 | Sep 5, 2023 |
| CVE-2023-20897 | Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker… | MEDIUM | 5.3 | Sep 5, 2023 |
| CVE-2021-33226 | Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py fil… | CRITICAL | 9.8 | Feb 17, 2023 |
| CVE-2022-22967 | An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously author… | HIGH | 7.7 | Jun 22, 2022 |
| CVE-2022-22941 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user co… | HIGH | 8.8 | Mar 29, 2022 |
| CVE-2022-22936 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, w… | HIGH | 8.8 | Mar 29, 2022 |
| CVE-2022-22935 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to for… | LOW | 3.7 | Mar 29, 2022 |
| CVE-2022-22934 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which c… | HIGH | 8.7 | Mar 29, 2022 |
| CVE-2021-22004 | salt: allows malacious actor to subvert the proper behaviour of the given minion software | HIGH | 7.5 | Sep 8, 2021 |
| CVE-2021-21996 | salt: user having control of source and source_hash URLs leads to root access | HIGH | 7.5 | Sep 8, 2021 |
| CVE-2021-31607 | salt: Command injection in the snapper module | HIGH | 7.8 | Apr 23, 2021 |
| CVE-2021-25315 | salt-api unauthenticated remote code execution | CRITICAL | 9.8 | Mar 3, 2021 |
| CVE-2021-3197 | salt: Shell injection by including ProxyCommand in an argument | CRITICAL | 9.8 | Feb 27, 2021 |
| CVE-2021-3148 | salt: Command injection in salt.utils.thin.gen_thin() | CRITICAL | 9.8 | Feb 27, 2021 |
| CVE-2021-3144 | salt: eauth tokens can be used once after expiration | CRITICAL | 9.1 | Feb 27, 2021 |
| CVE-2021-25284 | salt: webutils write passwords in cleartext to /var/log/salt/minion | MEDIUM | 4.4 | Feb 27, 2021 |
| CVE-2021-25283 | salt: Jinja renderer does not protect against server-side template injection attacks | CRITICAL | 9.8 | Feb 27, 2021 |
| CVE-2021-25282 | salt: Directory traversal in wheel.pillar_roots.write | HIGH | 8.8 | Feb 27, 2021 |
| CVE-2021-25281 | salt: API does not honor eAuth credentials for the wheel_async client | CRITICAL | 9.8 | Feb 27, 2021 |
| CVE-2020-35662 | salt: Certain modules do not always validated SSL certificates | HIGH | 7.4 | Feb 27, 2021 |
| CVE-2020-28972 | salt: Authentication to vCenter, vSphere, and ESXi servers does not always validate the SSL/TLS certificate | HIGH | 8.2 | Feb 27, 2021 |
| CVE-2020-28243 | salt: Privilege escalation on a minion when an unprivileged user is able to create files in any non-blacklisted directory | HIGH | 7.8 | Feb 27, 2021 |
| CVE-2020-25592 | salt: salt-netapi improperly validates eauth credentials and tokens | CRITICAL | 9.8 | Nov 6, 2020 |
| CVE-2020-17490 | salt: creates certificates with weak file permissions | MEDIUM | 5.5 | Nov 6, 2020 |
Showing 1 to 25 of 52 CVEs