Known vulnerabilities in Salt 3000

Vendor: SaltStack
Software: Salt
Version: 3000
Software CPE: cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
Total vulnerabilities: 31
Public exploits: 7
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Salt version 3000 Salt 3000 is affected by 31 vulnerabilities: 1 critical, 4 high, 13 medium, 13 low Critical High Medium Low

Vulnerabilities (31)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU111859 - Improper input validation
CVE-2025-22242
CWE-20 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111858 - Permissions, Privileges, and Access Controls
CVE-2025-22241
CWE-264 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111857 - Permissions, Privileges, and Access Controls
CVE-2025-22240
CWE-264 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111856 - Insufficient Verification of Data Authenticity
CVE-2025-22239
CWE-345 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111855 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-22238
CWE-22 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062343
and 8 more
#VU111854 - Improper Authorization
CVE-2025-22237
CWE-285 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU111852 - Improper Authentication
CVE-2024-38825
CWE-287 Medium
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU111851 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-38824
CWE-22 Medium
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062340
and 8 more
#VU111850 - Insufficient Verification of Data Authenticity
CVE-2024-38823
CWE-345 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU111849 - Improper Authentication
CVE-2024-38822
CWE-287 Low
No
No
3007.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU108745 - Integer overflow
CVE-2025-29087
CWE-190 Medium
No
No
3007.4 07.05.2025 SB2025050709
SB2025050710
SB2025050714
and 14 more
#VU86612 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-22232
CWE-22 Medium
No
No
3005.5, 3006.6 20.02.2024 SB2024022022
SB2024022023
SB2024022024
and 14 more
#VU86611 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-22231
CWE-22 Low
No
No
3005.5, 3006.6 20.02.2024 SB2024022022
SB2024022023
SB2024022024
and 13 more
#VU80472 - Permissions, Privileges, and Access Controls
CVE-2023-20898
CWE-264 Low
No
No
3005.2, 3006.2 05.09.2023 SB2023090559
SB2023090563
SB2023090601
and 13 more
#VU80471 - Improper input validation
CVE-2023-20897
CWE-20 Medium
No
No
3005.2, 3006.2 05.09.2023 SB2023090559
SB2023090563
SB2023090601
and 14 more
#VU58292 - Command injection
CVE-2021-31607
CWE-77 Low
No
No
3001.8, 3002.7 23.11.2021 SB2021042332
SB2021112302
SB2021052114
and 24 more
#VU50988 - Permissions, Privileges, and Access Controls
CVE-2020-28243
CWE-264 Medium
Public exploit available
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50982 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-25283
CWE-94 High
No
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50981 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-3197
CWE-78 High
No
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more
#VU50980 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-25282
CWE-22 Medium
Public exploit available
No
3000.8, 3001.6, 3002.5 28.02.2021 SB2021022809
SB2021022810
SB2021032201
and 29 more


Showing elements 1 - 20 out of 31