Salt vulnerable to directory traversal attack in minion file cache creation
Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.
02 / AFFECTED SOFTWARE
Affected packages
20 explicit affected versions
20 explicit affected versions
04 / EVIDENCE
Source records
Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.
Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.
05 / REFERENCES
Further evidence
- https://docs.saltproject.io/en/3006/topics/releases/3006.12.html
- https://docs.saltproject.io/en/3007/topics/releases/3007.4.html
- https://github.com/saltstack/salt
- https://github.com/saltstack/salt/commit/4b30218edf1a979855ea191d72b30c89f4a5a582
- https://nvd.nist.gov/vuln/detail/CVE-2025-22238
- https://github.com/advisories/GHSA-r546-h3ff-q585
- https://pypi.org/project/salt