saltproject-2023-08-09-advisory: ATTENTION! Some medium severity vulnerabilities have been discovered in Salt versions 3006.1 and earlier
Dear Salt users and Salt Project Community members, Some medium rated vulnerabilities have been discovered in Salt versions 3006.1 and earlier. The vulnerabilities are a Medium rating based on the Common Vulnerability Scoring System (CVSS). We are preparing a CVE release to be available on Thursday, August 10th. The CVE packages will be available for 3005.2 and 3006.2. The releases will contain the fixes available to resolve and remediate the identified vulnerabilities. We advise all users to quickly apply the CVE release as soon as the packages are available. Please reach out if you have any questions or comments. You can reach us at saltproject-security.pdl@broadcom.com. Thank you, Your Salt Open Core team
Other sources
Some medium severity vulnerabilities have been discovered in Salt versions 3006.1 and earlier. The vulnerabilities are medium severity based on the common Vulnerability Scoring System (CVSS).
— Salt Project
Affected Software
Event History
Frequently Asked Questions
What is the severity of saltproject-2023-08-09-advisory?
The severity of saltproject-2023-08-09-advisory is classified as Medium based on the CVSS.
Which versions are affected by saltproject-2023-08-09-advisory?
Salt versions 3006.1 and earlier are affected by saltproject-2023-08-09-advisory.
How do I fix saltproject-2023-08-09-advisory?
To fix saltproject-2023-08-09-advisory, upgrade to a version of Salt newer than 3006.1.
What are the risks of not addressing saltproject-2023-08-09-advisory?
Not addressing saltproject-2023-08-09-advisory may expose systems to potential exploitation and impact security.
Where can I find more information about saltproject-2023-08-09-advisory?
More information about saltproject-2023-08-09-advisory can be found in the official advisory on the Salt Project website.