VulnSea

salt vulnerabilities

CVEs whose affected-version data names the salt package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2025-62349Medium· 6.2
7mo ago

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

Sunlitsalt · saltEPSS 0.43%via OSV
CVE-2025-62348High· 7.8
7mo ago

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Twilightsalt · saltEPSS 0.19%via OSV
CVE-2025-22240Medium· 6.3
1y ago

Salt allows arbitrary directory creation or file deletion

Salt allows arbitrary directory creation or file deletion

Sunlitsalt · saltEPSS 0.16%via OSV
CVE-2025-22238Medium· 4.2
1y ago

Salt vulnerable to directory traversal attack in minion file cache creation

Salt vulnerable to directory traversal attack in minion file cache creation

Sunlitsalt · saltEPSS 0.29%via OSV
CVE-2025-22236High· 8.1
1y ago

Salt has minion event bus authorization bypass vulnerability

Salt has minion event bus authorization bypass vulnerability

Twilightsalt · saltEPSS 0.17%via OSV
CVE-2025-22237Medium· 6.7
1y ago

Salt's on demand pillar functionality vulnerable to arbitrary command injections

Salt's on demand pillar functionality vulnerable to arbitrary command injections

Sunlitsalt · saltEPSS 0.18%via OSV
CVE-2025-22239High· 8.1
1y ago

Salt vulnerable to arbitrary event injection

Salt vulnerable to arbitrary event injection

Twilightsalt · saltEPSS 0.18%via OSV
CVE-2025-22242Medium· 5.6
1y ago

Salt's worker process vulnerable to denial of service through file read operation

Salt's worker process vulnerable to denial of service through file read operation

Sunlitsalt · saltEPSS 0.14%via OSV
CVE-2025-22241Medium· 5.6
1y ago

Salt's file contents overwrite the VirtKey class

Salt's file contents overwrite the VirtKey class

Sunlitsalt · saltEPSS 0.18%via OSV
CVE-2024-38825Medium· 6.4
1y ago

Salt's salt.auth.pki module does not properly authenticate callers

Salt's salt.auth.pki module does not properly authenticate callers

Sunlitsalt · saltEPSS 0.15%via OSV
CVE-2023-34049Medium· 6.7
1y ago

Salt preflight script could be attacker controlled

Salt preflight script could be attacker controlled

Sunlitsalt · saltEPSS 0.19%via OSV
CVE-2024-22231Medium· 5.0
2y ago

Directory creation by malicious user in saltstack

Directory creation by malicious user in saltstack

Sunlitsalt · saltEPSS 0.69%via OSV
CVE-2024-22232High· 7.7
2y ago

Path traversal in saltstack

Path traversal in saltstack

Twilightsalt · saltEPSS 0.84%via OSV
CVE-2017-12791Critical· 9.8
4y ago

SaltStack Salt Directory traversal vulnerability in minion id validation

SaltStack Salt Directory traversal vulnerability in minion id validation

Midnightsalt · saltEPSS 4.1%via OSV
CVE-2013-2228High· 8.1
4y ago

SaltStack RSA Key Generation allows remote users to decrypt communications

SaltStack RSA Key Generation allows remote users to decrypt communications

Twilightsalt · saltEPSS 2.0%via OSV
salt vulnerabilities (CVEs) · VulnSea