Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

1 – 10 of 59 results


CVE-2024-22232

Medium priority
Needs evaluation

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-22231

Medium priority
Needs evaluation

Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-34049

Medium priority
Needs evaluation

[allows an attacker to force Salt-SSH to run their script]

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-20898

Medium priority
Needs evaluation

Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that uses Git Providers with different environments can get garbage data or...

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-20897

Medium priority
Needs evaluation

Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-28370

Medium priority

Some fixes available 2 of 11

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

2 affected packages

python-tornado, salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
python-tornado Not affected Needs evaluation Needs evaluation Needs evaluation Fixed
salt Not in release Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2022-22967

Medium priority
Needs evaluation

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their...

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-22941

Low priority
Needs evaluation

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the...

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-22936

Medium priority
Needs evaluation

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions...

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-22935

Low priority
Needs evaluation

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.

1 affected packages

salt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
salt Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages