HIGH7.7
PYSEC-2026-1891
Path traversal in saltstack
Quick fix
PYSEC-2026-1891 — salt: upgrade to the fixed version with the command below.
pip install --upgrade 'salt>=3005.5'Details
A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-22232[ADVISORY]
- https://github.com/saltstack/salt/commit/e0cdb80b55123f4a024759ffcf2b3f0e0788e7ab[WEB]
- https://github.com/saltstack/salt[PACKAGE]
- https://saltproject.io/security-announcements/2024-01-31-advisory[WEB]
- https://pypi.org/project/salt[PACKAGE]
- https://github.com/advisories/GHSA-2qw3-2wv6-p64x[ADVISORY]