Known vulnerabilities in Salt

Vendor: SaltStack
Software: Salt
Software CPE: cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
Total vulnerabilities: 60
Public exploits: 7
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Salt Salt is affected by 60 known vulnerabilities: 1 critical, 9 high, 20 medium, 30 low Critical High Medium Low

Vulnerabilities (60)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU120229 - Improper Authentication
CVE-2025-62349
CWE-287 Low
No
No
3006.18, 3007.10 19.12.2025 SB2025121950
SB2025121951
SB2025121952
and 32 more
#VU120228 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-62348
CWE-94 Medium
No
No
3006.18, 3007.10 19.12.2025 SB2025121950
SB2025121951
SB2025121952
and 32 more
#VU111859 - Improper input validation
CVE-2025-22242
CWE-20 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111858 - Permissions, Privileges, and Access Controls
CVE-2025-22241
CWE-264 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111857 - Permissions, Privileges, and Access Controls
CVE-2025-22240
CWE-264 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111856 - Insufficient Verification of Data Authenticity
CVE-2025-22239
CWE-345 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111855 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-22238
CWE-22 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062343
and 8 more
#VU111854 - Improper Authorization
CVE-2025-22237
CWE-285 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU111853 - Improper Authorization
CVE-2025-22236
CWE-285 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111852 - Improper Authentication
CVE-2024-38825
CWE-287 Medium
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU111851 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-38824
CWE-22 Medium
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111850 - Insufficient Verification of Data Authenticity
CVE-2024-38823
CWE-345 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU111849 - Improper Authentication
CVE-2024-38822
CWE-287 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU108745 - Integer overflow
CVE-2025-29087
CWE-190 Medium
No
No
3007.4 07.05.2025 SB2025050709
SB2025050710
SB2025050714
and 14 more
#VU86612 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-22232
CWE-22 Medium
No
No
3005.5, 3006.6 20.02.2024 SB2024022022
SB2024022023
SB2024022024
and 14 more
#VU86611 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-22231
CWE-22 Low
No
No
3005.5, 3006.6 20.02.2024 SB2024022022
SB2024022023
SB2024022024
and 13 more
#VU82944 - UNIX Symbolic Link (Symlink) Following
CVE-2023-34049
CWE-61 Low
No
No
3005.4, 3006.4 09.11.2023 SB2023110931
SB2023110932
SB2023110933
and 17 more
#VU82800 - Cryptographic Issues
CVE-2022-22934
CWE-310 Low
No
No
3002.8, 3003.4, 3004.1 07.11.2023 SB2022032942
SB2023110714
SB2022033035
and 21 more
#VU80472 - Permissions, Privileges, and Access Controls
CVE-2023-20898
CWE-264 Low
No
No
3005.2, 3006.2 05.09.2023 SB2023090559
SB2023090563
SB2023090601
and 13 more
#VU80471 - Improper input validation
CVE-2023-20897
CWE-20 Medium
No
No
3005.2, 3006.2 05.09.2023 SB2023090559
SB2023090563
SB2023090601
and 14 more


Showing elements 1 - 20 out of 60