Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
saltstack vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2018-15750
Directory Traversal vulnerability in salt-api in SaltStack Salt prior to 2017.7.8 and 2018.3.x prior to 2018.3.3 allows remote malicious users to determine which files exist on the server.
Saltstack Salt
668
VMScore
CVE-2018-15751
SaltStack Salt prior to 2017.7.8 and 2018.3.x prior to 2018.3.3 allow remote malicious users to bypass authentication and execute arbitrary commands via salt-api(netapi).
Saltstack Salt
517
VMScore
CVE-2022-22934
An issue exists in SaltStack Salt in versions prior to 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
Saltstack Salt
605
VMScore
CVE-2018-1999027
An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and previous versions in SaltAPIBuilder.java, SaltAPIStep.java that allows malicious users to capture credentials with a known credentials ID stored in Jenkins.
Jenkins Saltstack
668
VMScore
CVE-2017-7893
In SaltStack Salt prior to 2016.3.6, compromised salt-minions can impersonate the salt-master.
Saltstack Salt
409
VMScore
CVE-2021-25315
CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local malicious users to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP ...
Saltstack Salt
384
VMScore
CVE-2022-22935
An issue exists in SaltStack Salt in versions prior to 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM malicious user to force a minion process to stop by impersonating a master.
Saltstack Salt
482
VMScore
CVE-2022-22936
An issue exists in SaltStack Salt in versions prior to 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be re-play...
Saltstack Salt
535
VMScore
CVE-2022-22941
An issue exists in SaltStack Salt in versions prior to 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targ...
Saltstack Salt
580
VMScore
CVE-2022-22967
An issue exists in SaltStack Salt in versions prior to 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts ...
Saltstack Salt
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »