VYPR

Salt

by Saltstack

pypi: salt

Source repositories

CVEs (66)

  • CVE-2019-1010259CriJul 18, 2019
    risk 0.57cvss 9.8epss 0.02

    SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is:…

  • CVE-2018-15751CriOct 24, 2018
    risk 0.57cvss 9.8epss 0.05

    SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).

  • CVE-2017-14695CriOct 24, 2017
    risk 0.57cvss 9.8epss 0.03

    Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability…

  • CVE-2017-5200HigSep 26, 2017
    risk 0.57cvss 8.8epss 0.03

    Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.

  • CVE-2017-5192HigSep 26, 2017
    risk 0.57cvss 8.8epss 0.02

    When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.

  • CVE-2024-38824CriJun 13, 2025
    risk 0.55cvss 9.6epss 0.01

    Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.

  • CVE-2025-22236HigJun 13, 2025
    risk 0.53cvss 8.1epss 0.00

    Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

  • CVE-2016-1866HigApr 12, 2016
    risk 0.53cvss 8.1epss 0.02

    Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

  • CVE-2021-31607HigApr 23, 2021
    risk 0.51cvss 7.8epss 0.04

    In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the…

  • CVE-2020-28243HigFeb 27, 2021
    risk 0.51cvss 7.8epss 0.04

    An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

  • CVE-2017-8109HigApr 25, 2017
    risk 0.51cvss 7.8epss 0.00

    The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).

  • CVE-2021-21996HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

  • CVE-2015-4017HigAug 25, 2017
    risk 0.49cvss 7.5epss 0.01

    Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.

  • CVE-2020-35662HigFeb 27, 2021
    risk 0.48cvss 7.4epss 0.03

    In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.

  • CVE-2025-22239HigJun 13, 2025
    risk 0.46cvss 8.1epss 0.00

    Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.

  • CVE-2024-22232HigJun 27, 2024
    risk 0.43cvss 7.7epss 0.01

    A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.

  • CVE-2021-22004MedSep 8, 2021
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion…

  • CVE-2017-14696HigOct 24, 2017
    risk 0.42cvss 7.5epss 0.03

    SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.

  • CVE-2020-28972MedFeb 27, 2021
    risk 0.39cvss 5.9epss 0.03

    In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.

  • CVE-2025-22237MedJun 13, 2025
    risk 0.37cvss 6.7epss 0.00

    An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.