VDB
KO
CRITICAL 9.6

GHSA-8pcp-r83j-fc92

Salt vulnerable to directory traversal attack in file receiving method

Details

Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / salt
Introduced in: 3007.0rc1 Fixed in: 3007.4
Fix pip install --upgrade 'salt>=3007.4'
PyPI / salt
Introduced in: 3006.0rc1 Fixed in: 3006.12
Fix pip install --upgrade 'salt>=3006.12'

References