salt vulnerabilities
CVEs whose affected-version data names the salt package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
CVE-2025-62349Medium· 6.2Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
CVE-2025-62348High· 7.8Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
CVE-2025-22240Medium· 6.3Salt allows arbitrary directory creation or file deletion
Salt allows arbitrary directory creation or file deletion
CVE-2025-22238Medium· 4.2Salt vulnerable to directory traversal attack in minion file cache creation
Salt vulnerable to directory traversal attack in minion file cache creation
CVE-2025-22236High· 8.1Salt has minion event bus authorization bypass vulnerability
Salt has minion event bus authorization bypass vulnerability
CVE-2025-22237Medium· 6.7Salt's on demand pillar functionality vulnerable to arbitrary command injections
Salt's on demand pillar functionality vulnerable to arbitrary command injections
CVE-2025-22239High· 8.1Salt vulnerable to arbitrary event injection
Salt vulnerable to arbitrary event injection
CVE-2025-22242Medium· 5.6Salt's worker process vulnerable to denial of service through file read operation
Salt's worker process vulnerable to denial of service through file read operation
CVE-2025-22241Medium· 5.6Salt's file contents overwrite the VirtKey class
Salt's file contents overwrite the VirtKey class
CVE-2024-38825Medium· 6.4Salt's salt.auth.pki module does not properly authenticate callers
Salt's salt.auth.pki module does not properly authenticate callers
CVE-2023-34049Medium· 6.7Salt preflight script could be attacker controlled
Salt preflight script could be attacker controlled
CVE-2024-22231Medium· 5.0Directory creation by malicious user in saltstack
Directory creation by malicious user in saltstack
CVE-2024-22232High· 7.7Path traversal in saltstack
Path traversal in saltstack
CVE-2017-12791Critical· 9.8SaltStack Salt Directory traversal vulnerability in minion id validation
SaltStack Salt Directory traversal vulnerability in minion id validation
CVE-2013-2228High· 8.1SaltStack RSA Key Generation allows remote users to decrypt communications
SaltStack RSA Key Generation allows remote users to decrypt communications