CVE-2024-22231: Syndic cache directory creation is vulnerable to a directory traversal attack
Published Jun 27, 2024
·Updated
Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.
Affected Software
3 affected componentsFixes available
pip/salt>=3006.0<3006.6
3006.6
pip/salt<3005.5
3005.5
SaltStack Salt<3005.5, <3006.6
3005.53006.6
Remediation
Mitigation
Upgrade Salt masters to 3005.5 or 3006.6
Event History
Jun 27, 2024
CVE Published
via MITRE·06:51 AM
Data Sourced
via MITRE·06:51 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 AM
Weakness
Advisory Published
via GitHub·09:30 AM
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the severity of CVE-2024-22231?
CVE-2024-22231 is classified as a medium severity vulnerability due to the potential for unauthorized directory creation on a Salt master.
2
How do I fix CVE-2024-22231?
To fix CVE-2024-22231, update to Salt version 3006.6 or 3005.5 as they contain the necessary patches.
3
What type of attack does CVE-2024-22231 expose Salt to?
CVE-2024-22231 exposes Salt to a directory traversal attack that allows for arbitrary directory creation.
4
Which versions of Salt are affected by CVE-2024-22231?
CVE-2024-22231 affects Salt versions prior to 3006.6 and up to 3005.5.
5
Who is the vendor behind the product related to CVE-2024-22231?
The vendor related to CVE-2024-22231 is SaltStack.