saltproject-2024-01-30-advisory: ATTENTION! Some High and Medium severity vulnerabilities have been discovered in Salt versions 3006.5 and earlier
Dear Salt users and Salt Project community members, Some High and Medium rated vulnerabilities have been discovered in Salt versions 3006.5 and earlier. The vulnerabilities have a High and Medium rating based on the Common Vulnerability Scoring System (CVSS). We are preparing a CVE release that will be available on Wednesday, January 31. The CVE packages will be available for 3006.5 and 3005.4. The releases will contain the fix available to resolve and remediate the identified vulnerability. We advise all users to quickly apply the CVE release as soon as the packages are available. Please reach out if you have any questions or comments. You can reach us at saltproject-security.pdl@broadcom.com. Thank you, Your Salt Open Core team
Other sources
Some High and Medium severity vulnerabilities have been discovered in Salt versions 3006.5 and earlier. The vulnerabilities are high and medium severity based on the common Vulnerability Scoring System (CVSS).
— Salt Project
Affected Software
Event History
Frequently Asked Questions
What is the severity of saltproject-2024-01-30-advisory?
The severity of saltproject-2024-01-30-advisory is rated as High and Medium based on the Common Vulnerability Scoring System (CVSS).
How do I fix saltproject-2024-01-30-advisory?
To fix saltproject-2024-01-30-advisory, upgrade to Salt versions later than 3006.5.
What versions are affected by saltproject-2024-01-30-advisory?
Salt versions 3006.5 and earlier are affected by this advisory.
What types of vulnerabilities are included in saltproject-2024-01-30-advisory?
The advisory includes both High and Medium rated vulnerabilities discovered in Salt.
Who should be concerned about saltproject-2024-01-30-advisory?
All users and community members of the Salt Project using affected versions should be concerned about this advisory.