CVE-2024-38824: salt advisory
Published Jun 13, 2025
·Updated
Directory traversal vulnerability in recvfile method allows arbitrary files to be written to the master cache directory.
Affected Software
4 affected componentsFixes available
pip/salt>=3006.0rc1<3006.12
3006.12
pip/salt>=3007.0rc1<3007.4
3007.4
SaltStack Salt>=3006.0<3006.12
SaltStack Salt>=3007.0<3007.4
Event History
Jun 13, 2025
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
DescriptionSeverity
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
Affected Software
Advisory Published
via GitHub·09:30 AM
Data Sourced
via GitHub·09:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-38824?
CVE-2024-38824 is classified as a high severity vulnerability due to its potential for arbitrary file writing to the master cache directory.
2
How do I fix CVE-2024-38824?
To mitigate CVE-2024-38824, upgrade to salt version 3006.12 or 3007.4 or later.
3
What causes the CVE-2024-38824 vulnerability?
CVE-2024-38824 is caused by a directory traversal vulnerability in the recv_file method.
4
What platforms are affected by CVE-2024-38824?
CVE-2024-38824 affects pip installations of the salt package between versions 3006.0rc1 and 3006.12, as well as versions 3007.0rc1 and 3007.4.
5
Can CVE-2024-38824 lead to data loss?
Yes, CVE-2024-38824 could lead to data loss by allowing unauthorized access to files in the master's cache directory.