Lucene search

K
osvGoogleOSV:GHSA-VP49-2G4R-M3X3
HistoryMay 24, 2022 - 5:16 p.m.

SaltStack Salt is vulnerable Arbitrary Directory Access

2022-05-2417:16:58
Google
osv.dev
6

7.8 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

References