CVE-2024-22232: Specially crafted url can be created which leads to a directory traversal in the salt file server
Published Jun 27, 2024
·Updated
A specially crafted url can be created which leads to a directory traversal in the salt file server.
Affected Software
3 affected componentsFixes available
pip/salt>=3006.0<3006.6
3006.6
pip/salt<3005.5
3005.5
SaltStack Salt<3005.5, <3006.6
3005.53006.6
Remediation
Mitigation
Upgrade Salt masters to 3005.5 or 3006.6
Event History
Jun 27, 2024
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 AM
Weakness
Advisory Published
via GitHub·09:30 AM
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the severity of CVE-2024-22232?
CVE-2024-22232 is categorized as a critical vulnerability due to the potential for arbitrary file reads from the filesystem.
2
How do I fix CVE-2024-22232?
To mitigate CVE-2024-22232, upgrade to Salt version 3006.6 or 3005.5 as soon as possible.
3
What software versions are affected by CVE-2024-22232?
CVE-2024-22232 affects Salt versions between 3006.0 and 3006.6, as well as all versions up to 3005.5.
4
Can CVE-2024-22232 allow unauthorized access to sensitive files?
Yes, CVE-2024-22232 could enable a malicious user to read any file on the Salt master’s filesystem.
5
Is there a workaround for CVE-2024-22232 while awaiting a patch?
Currently, the best approach is to upgrade to the fixed versions, as no official workaround has been provided.