VendorsSaltStacksaltany version
Vulnerabilities

SaltStack Salt any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

44CVEs
CVE-2015-1838
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
Published 2017-04-13 · Modified
5.3EPSS 0.004
CVE-2021-25284
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
Published 2021-02-27 · Modified
4.4EPSS 0.005
CVE-2022-22935
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
Published 2022-03-29 · Modified
4.3EPSS 0.016
CVE-2015-8034
The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file.
Published 2017-01-30 · Modified
3.3EPSS 0.004
← Prev2 / 2