Known vulnerabilities in venv-salt-minion

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:venv-salt-minion:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 54
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting venv-salt-minion venv-salt-minion is affected by 54 known vulnerabilities: 5 high, 25 medium, 24 low Critical High Medium Low

Vulnerabilities (54)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144224 - Improper Handling of Exceptional Conditions
CVE-2026-27448
CWE-755 Medium
No
No
3006.0-1.76.1, 3006.0-2.31.2, 3006.0-2.49.2, 3006.0-2.80.1, 3006.0-3.95.1, 3006.0-150000.3.95.1 18.08.2026 SB2026081870
SB2026081877
SB2026081878
and 21 more
#VU144104 - Buffer overflow
CVE-2026-27459
CWE-120 High
No
No
3006.0-1.76.1, 3006.0-2.31.2, 3006.0-2.49.2, 3006.0-2.80.1, 3006.0-3.95.1, 3006.0-150000.3.95.1 18.08.2026 SB2026081845
SB2026081847
SB2026081877
and 16 more
#VU128147 - Resource exhaustion
CVE-2026-31958
CWE-400 Medium
No
No
3006.0-1.76.1, 3006.0-2.31.2, 3006.0-2.49.2, 3006.0-2.80.1, 3006.0-3.95.1, 3006.0-70002.5.12.1, 3006.0-80002.5.12.3, 3006.0-90002.5.12.2, 3006.0-120002.3.20.5, 3006.0-120002.5.12.1, 3006.0-150000.3.95.1, 3006.0-150002.5.12.2, 3006.0-160002.5.1, 3006.0-220402.3.18.1, 3006.0-240402.3.18.1 27.04.2026 SB20260427102
SB20260427109
SB20260427110
and 40 more
#VU124876 - Inefficient Regular Expression Complexity
CVE-2026-25547
CWE-1333 Low
No
No
3006.0-159000.5.3.2 06.04.2026 SB2026040628
SB2026040631
SB2026040632
and 13 more
#VU123311 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-1615
CWE-94 High
No
No
3006.0-159000.5.3.2 27.02.2026 SB2026022707
SB2026022708
SB2026032720
and 4 more
#VU123310 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-61140
CWE-1321 High
No
No
3006.0-159000.5.3.2 27.02.2026 SB2026022706
SB2026022708
SB2026030405
and 3 more
#VU123174 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-27606
CWE-22 High
Available
No
3006.0-159000.5.3.2 24.02.2026 SB2026022445
SB2026040631
SB2026040632
and 2 more
#VU122756 - Improper Access Control
CVE-2026-21722
CWE-284 Low
No
No
3006.0-159000.5.3.2 12.02.2026 SB2026021238
SB20260325198
SB2026040631
and 1 more
#VU120229 - Improper Authentication
CVE-2025-62349
CWE-287 Low
No
No
3006.0-1.64.1, 3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.19.1, 3006.0-2.22.1, 3006.0-2.37.1, 3006.0-2.40.2, 3006.0-2.68.1, 3006.0-2.71.1, 3006.0-2.77.1, 3006.0-3.81.1, 3006.0-3.84.1, 3006.0-70002.5.6.1, 3006.0-80002.5.6.1, 3006.0-80052.6.3.2, 3006.0-90002.5.6.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.14.2, 3006.0-120002.5.6.1, 3006.0-150000.3.83.1, 3006.0-150000.3.86.1, 3006.0-150002.5.6.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.12.1, 3006.0-240402.3.12.1 19.12.2025 SB2025121950
SB2025121951
SB2025121952
and 32 more
#VU120228 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-62348
CWE-94 Medium
No
No
3006.0-1.64.1, 3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.19.1, 3006.0-2.22.1, 3006.0-2.37.1, 3006.0-2.40.2, 3006.0-2.68.1, 3006.0-2.71.1, 3006.0-2.77.1, 3006.0-3.81.1, 3006.0-3.84.1, 3006.0-70002.5.6.1, 3006.0-80002.5.6.1, 3006.0-80052.6.3.2, 3006.0-90002.5.6.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.14.2, 3006.0-120002.5.6.1, 3006.0-150000.3.83.1, 3006.0-150000.3.86.1, 3006.0-150002.5.6.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.12.1, 3006.0-240402.3.12.1 19.12.2025 SB2025121950
SB2025121951
SB2025121952
and 32 more
#VU119885 - Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2025-67724
CWE-644 Low
No
No
3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.22.1, 3006.0-2.40.2, 3006.0-2.71.1, 3006.0-3.84.1, 3006.0-70002.5.9.1, 3006.0-80002.5.9.1, 3006.0-80052.6.3.2, 3006.0-90002.5.9.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.17.1, 3006.0-120002.5.9.1, 3006.0-150000.3.86.1, 3006.0-150002.5.9.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.15.3, 3006.0-240402.3.15.3 12.12.2025 SB2025121205
SB2026010587
SB2026010938
and 35 more
#VU119884 - Excessive Iteration
CVE-2025-67725
CWE-834 Low
No
No
3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.22.1, 3006.0-2.40.2, 3006.0-2.71.1, 3006.0-3.84.1, 3006.0-70002.5.9.1, 3006.0-80002.5.9.1, 3006.0-80052.6.3.2, 3006.0-90002.5.9.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.17.1, 3006.0-120002.5.9.1, 3006.0-150000.3.86.1, 3006.0-150002.5.9.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.15.3, 3006.0-240402.3.15.3 12.12.2025 SB2025121205
SB2026010587
SB2026010938
and 41 more
#VU119883 - Excessive Iteration
CVE-2025-67726
CWE-834 Medium
No
No
3006.0-1.67.1, 3006.0-2.9.1, 3006.0-2.9.3, 3006.0-2.22.1, 3006.0-2.40.2, 3006.0-2.71.1, 3006.0-3.84.1, 3006.0-70002.5.9.1, 3006.0-80002.5.9.1, 3006.0-80052.6.3.2, 3006.0-90002.5.9.1, 3006.0-90052.6.3.1, 3006.0-100052.3.3.1, 3006.0-120002.3.17.1, 3006.0-120002.5.9.1, 3006.0-150000.3.86.1, 3006.0-150002.5.9.1, 3006.0-150052.5.3.1, 3006.0-159000.5.3.2, 3006.0-220402.3.15.3, 3006.0-240402.3.15.3 12.12.2025 SB2025121205
SB2025123045
SB2026010587
and 41 more
#VU119233 - Resource exhaustion
CVE-2025-13836
CWE-400 Medium
No
No
3006.0-1.67.1, 3006.0-2.22.1, 3006.0-2.40.2, 3006.0-2.71.1, 3006.0-3.84.1, 3006.0-150000.3.86.1 06.12.2025 SB2025120602
SB20251226352
SB2025123104
and 36 more
#VU113081 - Exposure of sensitive information to an unauthorized actor
CVE-2025-3415
CWE-200 Medium
No
No
3006.0-159000.5.3.2 21.07.2025 SB2025072113
SB2025112453
SB2025112454
and 3 more
#VU111852 - Improper Authentication
CVE-2024-38825
CWE-287 Medium
No
No
3006.0-3.6.2, 3006.0-3.6.3, 3006.0-3.8.4 23.06.2025 SB2025062336
SB2025062338
SB2025062342
and 7 more
#VU109846 - Allocation of Resources Without Limits or Throttling
CVE-2025-47287
CWE-770 Medium
No
No
3006.0-3.6.2, 3006.0-3.6.3, 3006.0-3.8.4 27.05.2025 SB2025052726
SB2025052727
SB2025052728
and 30 more
#VU106253 - Improper input validation
CVE-2025-22870
CWE-20 Medium
Available
No
3006.0-70002.5.19.1, 3006.0-80002.5.19.1, 3006.0-90002.5.19.1 30.03.2025 SB2025033001
SB2025033002
SB2025033003
and 106 more
#VU88184 - Resource exhaustion
CVE-2023-45288
CWE-400 Medium
Available
No
3006.0-70002.5.19.1, 3006.0-80002.5.19.1, 3006.0-90002.5.19.1 05.04.2024 SB2024040533
SB2024040549
SB2024040551
and 189 more
#VU61599 - Improper input validation
CVE-2022-21698
CWE-20 Medium
No
No
3006.0-70002.5.19.1, 3006.0-80002.5.19.1, 3006.0-90002.5.19.1 24.03.2022 SB2022021530
SB2022032413
SB2022040807
and 110 more


Showing elements 1 - 20 out of 54