A specially crafted url can be created which leads to a directory traversal in the salt file server.
A malicious user can read an arbitrary file from a Salt master’s filesystem.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-22 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: vmware
Published: 2024-06-27T06:54:08.785Z
Updated: 2024-11-05T15:22:05.620Z
Reserved: 2024-01-08T16:40:16.141Z
Link: CVE-2024-22232

Updated: 2024-08-01T22:43:33.697Z

Status : Awaiting Analysis
Published: 2024-06-27T07:15:54.227
Modified: 2024-11-21T08:55:51.217
Link: CVE-2024-22232

No data.