saltstack
Security Risk Profile
62
/100
highSecurity Risk Score
Comprehensive risk assessment based on 99 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 5, 2013 to present
99
Total CVEs
43
Critical+High
3
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
62/100
high
⚠️ 3 Active Exploits
Severity Distribution
Critical
23High
20Medium
15Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Path Traversal
8
2
Input Validation
5
3
Command Injection
4
4
Infoleak
4
5
OS Command Injection
3
Most Affected Products
1. SaltStack Salt433
2. pip/salt194
3. Debian Debian Linux47
4. Fedoraproject Fedora34
5. debian/salt33
Recent Vulnerabilities
See more →EOL-salt-3008
unknown
5/27/2026
CVE-2024-38824
CVSS 9.6critical
salt advisory
6/13/2025
CVE-2023-34049
CVSS 6.7medium
Salt security advisory release - 2023-OCT-27
11/14/2024
EOL-salt-3006
unknown
7/30/2024
latest-version-salt-3006
unknown
7/30/2024
CVE-2024-22232
CVSS 7.7high
Specially crafted url can be created which leads to a directory traversal in the salt file server
6/27/2024
CVE-2024-22231
CVSS 5.0medium
Syndic cache directory creation is vulnerable to a directory traversal attack
6/27/2024
latest-version-salt-3007
unknown
3/6/2024
EOL-salt-3007
unknown
3/6/2024
saltproject-2024-01-31-advisory
unknown
Salt security advisory release - 2024-JAN-31
1/31/2024
Monitor saltstack in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.