Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18250 | Salt allows arbitrary directory creation or file deletion |
Github GHSA |
GHSA-xh32-3m67-qjgf | Salt allows arbitrary directory creation or file deletion |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 13 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
ssvc
|
Fri, 13 Jun 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the “tgt_env” variable. This can be exploited by an attacker to delete any file on the Master's process has permissions to. | |
| Title | CVE-2025-22240 salt advisory | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-06-13T13:42:42.561Z
Reserved: 2025-01-02T04:30:06.833Z
Link: CVE-2025-22240
Updated: 2025-06-13T13:41:57.274Z
Status : Deferred
Published: 2025-06-13T07:15:21.430
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-22240
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA