NA

CVE-2023-20898

Published: 05/09/2023 Updated: 14/09/2023
CVSS v3 Base Score: 7.8 | Impact Score: 6 | Exploitability Score: 1.1
VMScore: 0

Vulnerability Summary

Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters before 3005.2 or 3006.2. Anything that uses Git Providers with different environments can get garbage data or the wrong data, which can lead to wrongful data disclosure, wrongful executions, data corruption and/or crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt

Vendor Advisories

Debian Bug report logs - #1051504 salt: CVE-2023-20897 CVE-2023-20898 Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 8 Sep 2023 19:27:02 UTC Severity: grave Tags: security, upstream Found in ver ...