SaltStack RSA Key Generation allows remote users to decrypt communications
Modified: 7/6/2026
package
pkg:pypi/salt
SaltStack RSA Key Generation allows remote users to decrypt communications
Modified: 7/6/2026
SaltStack Salt SQL Injection vulnerability in mysql.user_chpass function
Modified: 10/25/2024
Command Injection in SaltStack Salt
Modified: 10/23/2024
SaltStack Salt Improper Validation of eauth credentials and tokens in salt-netapi
Modified: 10/22/2024
SaltStack Improper Verification of Cryptographic Signature
Modified: 10/26/2024
Path traversal in saltstack
Modified: 7/7/2026
SaltStack Salt Allows creating certificates with weak file permissions
Modified: 10/22/2024
Salt preflight script could be attacker controlled
Modified: 7/7/2026
Salt's salt.auth.pki module does not properly authenticate callers
Modified: 7/7/2026
SaltStack Salt Authentication Bypass by Capture-replay
Modified: 10/22/2024
SaltStack Salt Denial of Service via a crafted authentication request
Modified: 10/22/2024
SaltStack has insecure /tmp file handling in salt/modules/chef.py
Modified: 12/1/2024
Salt uses weak permissions on the cache data
Modified: 10/21/2024
SaltStack Salt Directory Traversal vulnerability
Modified: 10/26/2024
Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
Modified: 7/7/2026
Salt's file contents overwrite the VirtKey class
Modified: 7/7/2026
SaltStack Privilege Escalation vulnerability
Modified: 12/7/2024
Salt vulnerable to Improper Certificate Validation
Modified: 10/21/2024
Salt vulnerable to directory traversal attack in file receiving method
Modified: 6/29/2026
SaltStack Salt arbitrary command execution in Salt-api via ssh_client
Modified: 12/1/2024
SaltStack Salt is vulnerable to shell injection via ProxyCommand argument
Modified: 10/23/2024
Salt improper handling of tmp files
Modified: 12/1/2024
Salt's worker process vulnerable to denial of service through file read operation
Modified: 7/7/2026
Salt vulnerable to arbitrary event injection
Modified: 7/7/2026
SaltStack Salt Improper Authentication via Man in the Middle Attack
Modified: 10/22/2024
salt password information leaked in debug logs
Modified: 10/21/2024
SaltStack MITM SSH attack in salt-ssh
Modified: 10/26/2024
SaltStack Salt Authentication Bypass when using the local_batch client from salt-api
Modified: 10/21/2024
Salt's on demand pillar functionality vulnerable to arbitrary command injections
Modified: 7/7/2026
Salt's PAM auth fails to reject locked accounts
Modified: 10/26/2024
SaltStack Salt allows compromised salt-minions to impersonate the salt-master
Modified: 12/6/2024
SaltStack Salt command injection in the Salt-API when using the Salt-SSH client
Modified: 10/23/2024
Salt allows deleted minions to read or write to minions with the same id
Modified: 10/21/2024
SaltStack Salt Directory traversal vulnerability in minion id validation
Modified: 10/21/2024
Salt has minion event bus authorization bypass vulnerability
Modified: 7/7/2026
Minion identity not validated in saltstack
Modified: 12/6/2024
SaltStack Salt Directory Traversal vulnerability in salt-api
Modified: 10/23/2024
SaltStack Salt Insecure Temporary File Creation
Modified: 12/1/2024
Exposure of Resource to Wrong Sphere in salt
Modified: 10/22/2024
SaltStack Salt command injection via a crafted process name
Modified: 10/22/2024
SaltStack Salt Unauthenticated Remote Code Execution
Modified: 10/26/2024
Saltstack Salt Unauthenticated Arbitrary Code Execution
Modified: 4/9/2025
Directory creation by malicious user in saltstack
Modified: 7/7/2026
salt leaks git usernames and passwords to the log
Modified: 10/21/2024
SaltStack Salt is vulnerable to command injection
Modified: 10/22/2024
SaltStack Salt Permissions Bypass
Modified: 10/22/2024
SaltStack Salt Command Injection in netapi ssh client
Modified: 10/22/2025
SaltStack insecurely uses /tmp
Modified: 10/26/2024
Salt can cause Git Providers to get wrong data
Modified: 2/13/2025
SaltStack Salt Improper SSL Certificate Validation
Modified: 10/22/2024
Salt vulnerable to directory traversal attack in minion file cache creation
Modified: 7/7/2026
SaltStack Salt Cleartext Storage of Sensitive Information via cmdmod
Modified: 10/23/2024
Salt Insecure configuration of PAM external authentication service
Modified: 10/21/2024
Salt has insufficient argument validation in several modules
Modified: 10/26/2024
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
Modified: 7/7/2026
SaltStack Salt is vulnerable Arbitrary Directory Access
Modified: 10/22/2025
Salt vulnerable to denial of service
Modified: 2/13/2025
Salt Improper Access Control
Modified: 10/21/2024
SaltStack Salt eauth tokens can be used once after expiration
Modified: 10/23/2024
SaltStack Salt Improper Certificate Validation
Modified: 10/26/2024
SaltStack Salt Remote command execution and incorrect access control when using salt-api
Modified: 10/23/2024
SaltStack Salt Information Exposure
Modified: 10/26/2024
Improper Authentication in SaltStack Salt
Modified: 10/26/2024
SaltStack Salt Server Side Template Injection
Modified: 10/23/2024
Salt allows arbitrary directory creation or file deletion
Modified: 7/7/2026
SaltStack Salt Directory traversal vulnerability in minion id validation
Modified: 7/9/2026
SaltStack Salt Improper Authentication vulnerability
Modified: 10/23/2024
Modified: 6/10/2026
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 7/9/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 11/8/2023