VYPR

rpm package

suse/saltbundlepy-more-itertools&distro=SUSE:EL-9:Update:Products:SaltBundle:Update

pkg:rpm/suse/saltbundlepy-more-itertools&distro=SUSE:EL-9:Update:Products:SaltBundle:Update

Vulnerabilities (3)

  • CVE-2025-62349MedJan 30, 2026
    affected < 9.1.0-1.12.2fixed 9.1.0-1.12.2

    Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to p

  • CVE-2025-62348HigJan 30, 2026
    affected < 9.1.0-1.12.2fixed 9.1.0-1.12.2

    Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

  • CVE-2023-34049MedNov 14, 2024
    affected < 8.10.0-1.6.1fixed 8.10.0-1.6.1

    The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight script before it runs they can ensure Salt-SSH run