A malicious user can read an arbitrary file from a Salt master’s filesystem.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1887 | A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem. |
Github GHSA |
GHSA-2qw3-2wv6-p64x | Path traversal in saltstack |
Tue, 05 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
ssvc
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-11-05T15:22:05.620Z
Reserved: 2024-01-08T16:40:16.141Z
Link: CVE-2024-22232
Updated: 2024-08-01T22:43:33.697Z
Status : Deferred
Published: 2024-06-27T07:15:54.227
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-22232
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA