Known vulnerabilities in venv-salt-minion
Vendor:
SUSE
Software:
venv-salt-minion
Software CPE:
cpe:2.3:o:suse:venv-salt-minion:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
54
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3006.0-160002.6.1
3006.0-220402.3.25.1
3006.0-240402.3.25.1
3006.0-120002.3.27.1
3006.0-130002.2.10.1
3006.0-150002.5.19.1
3006.0-120002.5.19.1
3006.0-70002.5.19.1
3006.0-80002.5.19.1
3006.0-90002.5.19.1
3006.0-100002.1.10.1
3006.0-1.76.1
3006.0-2.31.2
3006.0-2.80.1
3006.0-2.49.2
3006.0-150000.3.95.1
3006.0-3.95.1
3006.0-100002.1.3.1
3006.0-150002.5.12.2
3006.0-120002.5.12.1
3006.0-70002.5.12.1
3006.0-80002.5.12.3
3006.0-90002.5.12.2
3006.0-220402.3.18.1
3006.0-240402.3.18.1
3006.0-120002.3.20.5
3006.0-130002.2.3.1
3006.0-160002.5.1
3006.0-100052.3.3.1
3006.0-159000.5.3.2
3006.0-150052.5.3.1
3006.0-2.9.3
3006.0-2.9.1
3006.0-80052.6.3.2
3006.0-90052.6.3.1
3006.0-1.67.1
3006.0-2.22.1
3006.0-2.71.1
3006.0-2.40.2
3006.0-150000.3.86.1
3006.0-3.84.1
3006.0-220402.3.15.3
3006.0-240402.3.15.3
3006.0-120002.3.17.1
3006.0-150002.5.9.1
3006.0-120002.5.9.1
3006.0-70002.5.9.1
3006.0-80002.5.9.1
3006.0-90002.5.9.1
3006.0-2.6.5
3006.0-2.6.2
3006.0-2.3.2
3006.0-2.3.1
3006.0-1.64.1
3006.0-2.37.1
3006.0-2.77.1
3006.0-2.68.1
3006.0-2.19.1
3006.0-150000.3.83.1
3006.0-3.81.1
3006.0-240402.3.12.1
3006.0-220402.3.12.1
3006.0-120002.3.14.2
3006.0-70002.5.6.1
3006.0-80002.5.6.1
3006.0-90002.5.6.1
3006.0-150002.5.6.1
3006.0-120002.5.6.1
3006.0-220402.3.9.4
3006.0-240402.3.9.7
3006.0-120002.3.11.3
3006.0-150002.5.3.3
3006.0-120002.5.3.5
3006.0-70002.5.3.3
3006.0-80002.5.3.15
3006.0-90002.5.3.9
3006.0-3.6.2
3006.0-3.6.3
3006.0-3.8.4
3006.0-3.3.7
3006.0-3.3.5
3006.0-3.5.3
3006.0-1.53.2
3006.0-2.29.2
3006.0-2.69.2
3006.0-2.60.2
3006.0-2.11.1
3006.0-150000.3.75.5
3006.0-3.73.1
3006.0-1.50.1
3006.0-2.26.1
3006.0-2.57.2
3006.0-2.66.1
3006.0-150000.3.72.1
3006.0-3.68.1
3006.0-1.47.1
3006.0-2.23.1
3006.0-2.61.1
3006.0-2.54.3
3006.0-2.63.3
3006.0-150000.3.67.1
3006.0-3.65.1
3006.0-1.44.1
3006.0-2.20.1
3006.0-2.58.1
3006.0-2.51.1
3006.0-2.60.1
3006.0-150000.3.62.2
3006.0-3.60.3
3006.0-1.41.1
3006.0-2.17.1
3006.0-2.55.1
3006.0-2.48.1
3006.0-2.57.1
3006.0-150000.3.59.1
3006.0-3.57.1
3006.0-1.36.3
3006.0-2.12.3
3006.0-2.50.4
3006.0-2.43.3
3006.0-2.52.3
3006.0-150000.3.54.3
3006.0-3.52.3
3006.0-3.46.2
3006.0-150000.3.48.2
3006.0-2.46.4
3006.0-2.44.4
3006.0-2.6.3
3006.0-1.30.3
3006.0-2.40.1
3006.0-3.40.1
3006.0-150000.3.42.1
3006.0-2.38.1
3006.0-1.24.1
3006.0-3.33.2
3006.0-2.33.1
3006.0-1.19.2
3006.0-150000.3.35.1
3004-2.9.2
3004-3.9.1
3004-2.9.1
3004-159000.3.9.1
3004-3.11.1
3004-150000.3.11.1
3004-2.11.2
Vulnerabilities (54)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU144224 - Improper Handling of Exceptional Conditions CVE-2026-27448 |
CWE-755 | Medium | 3006.0-1.76.1, 3006.0-2.31.2, 3006.0-2.49.2, 3006.0-2.80.1, 3006.0-3.95.1, 3006.0-150000.3.95.1 | 18.08.2026 |
SB2026081870 SB2026081877 SB2026081878 and 21 more |
||
| #VU144104 - Buffer overflow CVE-2026-27459 |
CWE-120 | High | 3006.0-1.76.1, 3006.0-2.31.2, 3006.0-2.49.2, 3006.0-2.80.1, 3006.0-3.95.1, 3006.0-150000.3.95.1 | 18.08.2026 |
SB2026081845 SB2026081847 SB2026081877 and 16 more |
||
| #VU128147 - Resource exhaustion CVE-2026-31958 |
CWE-400 | Medium | 3006.0-1.76.1, 3006.0-2.31.2, 3006.0-2.49.2, 3006.0-2.80.1, 3006.0-3.95.1, 3006.0-70002.5.12.1, 3006.0-80002.5.12.3, 3006.0-90002.5.12.2, 3006.0-120002.3.20.5, 3006.0-120002.5.12.1, 3006.0-150000.3.95.1, 3006.0-150002.5.12.2, 3006.0-160002.5.1, 3006.0-220402.3.18.1, 3006.0-240402.3.18.1 | 27.04.2026 |
SB20260427102 SB20260427109 SB20260427110 and 40 more |
||
| #VU124876 - Inefficient Regular Expression Complexity CVE-2026-25547 |
CWE-1333 | Low | 3006.0-159000.5.3.2 | 06.04.2026 |
SB2026040628 SB2026040631 SB2026040632 and 13 more |
||
| #VU123311 - Improper Control of Generation of Code ('Code Injection') CVE-2026-1615 |
CWE-94 | High | 3006.0-159000.5.3.2 | 27.02.2026 |
SB2026022707 SB2026022708 SB2026032720 and 4 more |
||
| #VU123310 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2025-61140 |
CWE-1321 | High | 3006.0-159000.5.3.2 | 27.02.2026 |
SB2026022706 SB2026022708 SB2026030405 and 3 more |
||
| #VU123174 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-27606 |
CWE-22 | High | 3006.0-159000.5.3.2 | 24.02.2026 |
SB2026022445 SB2026040631 SB2026040632 and 2 more |
||
| #VU122756 - Improper Access Control CVE-2026-21722 |
CWE-284 | Low | 3006.0-159000.5.3.2 | 12.02.2026 |
SB2026021238 SB20260325198 SB2026040631 and 1 more |
||
| #VU120229 - Improper Authentication CVE-2025-62349 |
CWE-287 | Low | 3006.0-1.64.1, 3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.19.1, 3006.0-2.22.1, 3006.0-2.37.1, 3006.0-2.40.2, 3006.0-2.68.1, 3006.0-2.71.1, 3006.0-2.77.1, 3006.0-3.81.1, 3006.0-3.84.1, 3006.0-70002.5.6.1, 3006.0-80002.5.6.1, 3006.0-80052.6.3.2, 3006.0-90002.5.6.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.14.2, 3006.0-120002.5.6.1, 3006.0-150000.3.83.1, 3006.0-150000.3.86.1, 3006.0-150002.5.6.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.12.1, 3006.0-240402.3.12.1 | 19.12.2025 |
SB2025121950 SB2025121951 SB2025121952 and 32 more |
||
| #VU120228 - Improper Control of Generation of Code ('Code Injection') CVE-2025-62348 |
CWE-94 | Medium | 3006.0-1.64.1, 3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.19.1, 3006.0-2.22.1, 3006.0-2.37.1, 3006.0-2.40.2, 3006.0-2.68.1, 3006.0-2.71.1, 3006.0-2.77.1, 3006.0-3.81.1, 3006.0-3.84.1, 3006.0-70002.5.6.1, 3006.0-80002.5.6.1, 3006.0-80052.6.3.2, 3006.0-90002.5.6.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.14.2, 3006.0-120002.5.6.1, 3006.0-150000.3.83.1, 3006.0-150000.3.86.1, 3006.0-150002.5.6.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.12.1, 3006.0-240402.3.12.1 | 19.12.2025 |
SB2025121950 SB2025121951 SB2025121952 and 32 more |
||
| #VU119885 - Improper Neutralization of HTTP Headers for Scripting Syntax CVE-2025-67724 |
CWE-644 | Low | 3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.22.1, 3006.0-2.40.2, 3006.0-2.71.1, 3006.0-3.84.1, 3006.0-70002.5.9.1, 3006.0-80002.5.9.1, 3006.0-80052.6.3.2, 3006.0-90002.5.9.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.17.1, 3006.0-120002.5.9.1, 3006.0-150000.3.86.1, 3006.0-150002.5.9.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.15.3, 3006.0-240402.3.15.3 | 12.12.2025 |
SB2025121205 SB2026010587 SB2026010938 and 35 more |
||
| #VU119884 - Excessive Iteration CVE-2025-67725 |
CWE-834 | Low | 3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.22.1, 3006.0-2.40.2, 3006.0-2.71.1, 3006.0-3.84.1, 3006.0-70002.5.9.1, 3006.0-80002.5.9.1, 3006.0-80052.6.3.2, 3006.0-90002.5.9.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.17.1, 3006.0-120002.5.9.1, 3006.0-150000.3.86.1, 3006.0-150002.5.9.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.15.3, 3006.0-240402.3.15.3 | 12.12.2025 |
SB2025121205 SB2026010587 SB2026010938 and 41 more |
||
| #VU119883 - Excessive Iteration CVE-2025-67726 |
CWE-834 | Medium | 3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.22.1, 3006.0-2.40.2, 3006.0-2.71.1, 3006.0-3.84.1, 3006.0-70002.5.9.1, 3006.0-80002.5.9.1, 3006.0-80052.6.3.2, 3006.0-90002.5.9.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.17.1, 3006.0-120002.5.9.1, 3006.0-150000.3.86.1, 3006.0-150002.5.9.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.15.3, 3006.0-240402.3.15.3 | 12.12.2025 |
SB2025121205 SB2025123045 SB2026010587 and 41 more |
||
| #VU119233 - Resource exhaustion CVE-2025-13836 |
CWE-400 | Medium | 3006.0-1.67.1, 3006.0-2.22.1, 3006.0-2.40.2, 3006.0-2.71.1, 3006.0-3.84.1, 3006.0-150000.3.86.1 | 06.12.2025 |
SB2025120602 SB20251226352 SB2025123104 and 36 more |
||
| #VU113081 - Exposure of sensitive information to an unauthorized actor CVE-2025-3415 |
CWE-200 | Medium | 3006.0-159000.5.3.2 | 21.07.2025 |
SB2025072113 SB2025112453 SB2025112454 and 3 more |
||
| #VU111852 - Improper Authentication CVE-2024-38825 |
CWE-287 | Medium | 3006.0-3.6.2, 3006.0-3.6.3, 3006.0-3.8.4 | 23.06.2025 |
SB2025062336 SB2025062338 SB2025062342 and 7 more |
||
| #VU109846 - Allocation of Resources Without Limits or Throttling CVE-2025-47287 |
CWE-770 | Medium | 3006.0-3.6.2, 3006.0-3.6.3, 3006.0-3.8.4 | 27.05.2025 |
SB2025052726 SB2025052727 SB2025052728 and 30 more |
||
| #VU106253 - Improper input validation CVE-2025-22870 |
CWE-20 | Medium | 3006.0-70002.5.19.1, 3006.0-80002.5.19.1, 3006.0-90002.5.19.1 | 30.03.2025 |
SB2025033001 SB2025033002 SB2025033003 and 106 more |
||
| #VU88184 - Resource exhaustion CVE-2023-45288 |
CWE-400 | Medium | 3006.0-70002.5.19.1, 3006.0-80002.5.19.1, 3006.0-90002.5.19.1 | 05.04.2024 |
SB2024040533 SB2024040549 SB2024040551 and 189 more |
||
| #VU61599 - Improper input validation CVE-2022-21698 |
CWE-20 | Medium | 3006.0-70002.5.19.1, 3006.0-80002.5.19.1, 3006.0-90002.5.19.1 | 24.03.2022 |
SB2022021530 SB2022032413 SB2022040807 and 110 more |
Showing elements 1 - 20 out of 54