Bug | jessie | stretch | buster | Description |
---|
CVE-2024-22232 | vulnerable | vulnerable | vulnerable | A specially crafted url can be created which leads to a directory trav ... |
CVE-2024-22231 | vulnerable | vulnerable | vulnerable | Syndic cache directory creation is vulnerable to a directory traversal ... |
CVE-2023-34049 | vulnerable | vulnerable | vulnerable | The Salt-SSH pre-flight option copies the script to the target at a pr ... |
CVE-2023-28370 | vulnerable | vulnerable | vulnerable | Open redirect vulnerability in Tornado versions 6.3.1 and earlier allo ... |
CVE-2023-20898 | vulnerable | vulnerable | vulnerable | Git Providers can read from the wrong environment because they get the ... |
CVE-2023-20897 | vulnerable | vulnerable | vulnerable | Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. ... |
CVE-2022-22967 | vulnerable | vulnerable | vulnerable | An issue was discovered in SaltStack Salt in versions before 3002.9, 3 ... |
CVE-2022-22941 | vulnerable | vulnerable | vulnerable | An issue was discovered in SaltStack Salt in versions before 3002.8, 3 ... |
CVE-2022-22936 | vulnerable | vulnerable | vulnerable | An issue was discovered in SaltStack Salt in versions before 3002.8, 3 ... |
CVE-2022-22935 | vulnerable | vulnerable | vulnerable | An issue was discovered in SaltStack Salt in versions before 3002.8, 3 ... |
CVE-2022-22934 | vulnerable | vulnerable | vulnerable | An issue was discovered in SaltStack Salt in versions before 3002.8, 3 ... |
CVE-2017-14696 | vulnerable (no DSA) | fixed | fixed | SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7 ... |
CVE-2017-14695 | vulnerable (no DSA) | fixed | fixed | Directory traversal vulnerability in minion id validation in SaltStack ... |
CVE-2017-12791 | vulnerable (no DSA) | fixed | fixed | Directory traversal vulnerability in minion id validation in SaltStack ... |
CVE-2017-7893 | vulnerable (no DSA, ignored) | vulnerable (no DSA) | fixed | In SaltStack Salt before 2016.3.6, compromised salt-minions can impers ... |
CVE-2016-9639 | vulnerable (no DSA) | fixed | fixed | Salt before 2015.8.11 allows deleted minions to read or write to minio ... |
CVE-2016-3176 | vulnerable (no DSA) | fixed | fixed | Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external ... |
CVE-2015-8034 | vulnerable (no DSA) | fixed | fixed | The state.sls function in Salt before 2015.8.3 uses weak permissions o ... |
CVE-2015-6941 | vulnerable (no DSA) | fixed | fixed | win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before ... |
CVE-2015-6918 | vulnerable (no DSA) | fixed | fixed | salt before 2015.5.5 leaks git usernames and passwords to the log. |
Bug | Description |
---|
CVE-2021-31607 | In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerabi ... |
CVE-2021-25315 | CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Ent ... |
CVE-2021-25284 | An issue was discovered in through SaltStack Salt before 3002.5. salt. ... |
CVE-2021-25283 | An issue was discovered in through SaltStack Salt before 3002.5. The j ... |
CVE-2021-25282 | An issue was discovered in through SaltStack Salt before 3002.5. The s ... |
CVE-2021-25281 | An issue was discovered in through SaltStack Salt before 3002.5. salt- ... |
CVE-2021-21996 | An issue was discovered in SaltStack Salt before 3003.3. A user who ha ... |
CVE-2021-3197 | An issue was discovered in SaltStack Salt before 3002.5. The salt-api' ... |
CVE-2021-3148 | An issue was discovered in SaltStack Salt before 3002.5. Sending craft ... |
CVE-2021-3144 | In SaltStack Salt before 3002.5, eauth tokens can be used once after e ... |
CVE-2020-35662 | In SaltStack Salt before 3002.5, when authenticating to services using ... |
CVE-2020-28972 | In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsp ... |
CVE-2020-28243 | An issue was discovered in SaltStack Salt before 3002.5. The minion's ... |
CVE-2020-25592 | In SaltStack Salt through 3002, salt-netapi improperly validates eauth ... |
CVE-2020-17490 | The TLS module within SaltStack Salt through 3002 creates certificates ... |
CVE-2020-16846 | An issue was discovered in SaltStack Salt through 3002. Sending crafte ... |
CVE-2020-11652 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 bef ... |
CVE-2020-11651 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 bef ... |
CVE-2019-1010259 | SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impac ... |
CVE-2019-18897 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packagin ... |
CVE-2019-17361 | In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh ... |
CVE-2018-15751 | SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remo ... |
CVE-2018-15750 | Directory Traversal vulnerability in salt-api in SaltStack Salt before ... |
CVE-2017-8109 | The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 co ... |
CVE-2017-5200 | Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, ... |
CVE-2017-5192 | When using the local_batch client from salt-api in SaltStack Salt befo ... |
CVE-2016-1866 | Salt 2015.8.x before 2015.8.4 does not properly handle clear messages ... |
CVE-2015-4017 | Salt before 2014.7.6 does not verify certificates when connecting via ... |
CVE-2015-1839 | modules/chef.py in SaltStack before 2014.7.4 does not properly handle ... |
CVE-2015-1838 | modules/serverdensity_device.py in SaltStack before 2014.7.4 does not ... |
CVE-2014-3563 | Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 20 ... |
CVE-2013-6617 | The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not ... |
CVE-2013-4439 | Salt (aka SaltStack) before 0.15.0 through 0.17.0 allows remote authen ... |
CVE-2013-4438 | Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute ... |
CVE-2013-4437 | Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 h ... |
CVE-2013-4436 | The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 ... |
CVE-2013-4435 | Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated ... |
CVE-2013-2228 | SaltStack RSA Key Generation allows remote users to decrypt communicat ... |