Where
-Infinity
0

SaltStack Salt2 vulnerabilities

Risk 23
First published (updated )

Specially crafted url can be created which leads to a directory traversal in the salt file server

Risk 45
Severity
7.7
First published (updated )

Syndic cache directory creation is vulnerable to a directory traversal attack

Risk 27
Severity
5
First published (updated )

SaltStack SaltATTENTION! Some High and Medium severity vulnerabilities have been discovered in Salt versions 3006.5 and earlier

Risk 42
First published (updated )

SaltStack Salt1 vulnerability

Risk 23
First published (updated )

Salt security advisory release - 2023-OCT-27

Risk 62
Severity
6.7
First published (updated )

SaltStack SaltATTENTION! A Medium severity vulnerability has been discovered in Salt versions 3006.3 and earlier

Risk 35
First published (updated )

SaltStack Salt2 vulnerabilities

Risk 23
First published (updated )

Git Providers can read from the wrong environment because they get the same cache directory base nam…

Risk 68
Severity
7.8
First published (updated )

DOS in minion return.

Risk 28
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SaltStack SaltATTENTION! Some medium severity vulnerabilities have been discovered in Salt versions 3006.1 and earlier

Risk 35
First published (updated )

SaltStack SaltBuffer Overflow

Risk 86
Severity
9.8
First published (updated )

SaltStack Salt1 vulnerability

Risk 23
First published (updated )

PAM auth fails to reject locked accounts.

Risk 82
Severity
8.8
First published (updated )

SaltStack SaltAttention! A critical vulnerability has been discovered in Salt versions 3004.1 and earlier

Risk 49
First published (updated )

SaltStack Salt4 vulnerabilities

Risk 23
First published (updated )

Minion authentication denial of service.

Risk 23
Severity
4.3
First published (updated )

Job publishes and file server replies are susceptible to replay attacks.

Risk 82
Severity
8.8
First published (updated )

When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_…

Risk 82
Severity
8.8
First published (updated )

Salt Masters do not sign pillar data with the minion’s public key.

Risk 82
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SaltStack SaltATTENTION! Some critical vulnerabilities have been discovered in Salt versions 3004 and earlier

Risk 42
First published (updated )

SaltStack Salt3 vulnerabilities

Risk 23
First published (updated )

Race Condition

Risk 59
Severity
6.4
First published (updated )

A user who has control of the source, and source_hash URLs can gain full file system access as root …

Risk 73
Severity
7.5
First published (updated )

Command Injection, OS Command Injection

Risk 72
Severity
7.8
First published (updated )

SaltStack Saltsalt-api unauthenticated remote code execution

Risk 89
Severity
9.8
First published (updated )

SaltStack SaltLast updated 8 August 2024

Risk 27
Severity
4.4
First published (updated )

SaltStack SaltCode Injection

Risk 89
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SaltStack SaltLast updated 8 August 2024

Risk 37
Severity
5.9
First published (updated )

SaltStack SaltPath Traversal

Risk 69
Severity
9.1
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203