Safety vulnerability ID: 65902
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.
Latest version: 3007.1
Portable, distributed, remote execution and configuration management system
========================
Security
--------
- Fix CVE-2024-22231 Prevent directory traversal when creating syndic cache directory on the master.
- Fix CVE-2024-22232 Prevent directory traversal attacks in the master's serve_file method.
These vulnerablities were discovered and reported by:
Yudi Zhao(Huawei Nebula Security Lab),Chenwei Jiang(Huawei Nebula Security Lab) (565)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application