Known vulnerabilities in venv-salt-minion - page 3
Vendor:
SUSE
Software:
venv-salt-minion
Software CPE:
cpe:2.3:o:suse:venv-salt-minion:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
54
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3006.0-160002.6.1
3006.0-220402.3.25.1
3006.0-240402.3.25.1
3006.0-120002.3.27.1
3006.0-130002.2.10.1
3006.0-150002.5.19.1
3006.0-120002.5.19.1
3006.0-70002.5.19.1
3006.0-80002.5.19.1
3006.0-90002.5.19.1
3006.0-100002.1.10.1
3006.0-1.76.1
3006.0-2.31.2
3006.0-2.80.1
3006.0-2.49.2
3006.0-150000.3.95.1
3006.0-3.95.1
3006.0-100002.1.3.1
3006.0-150002.5.12.2
3006.0-120002.5.12.1
3006.0-70002.5.12.1
3006.0-80002.5.12.3
3006.0-90002.5.12.2
3006.0-220402.3.18.1
3006.0-240402.3.18.1
3006.0-120002.3.20.5
3006.0-130002.2.3.1
3006.0-160002.5.1
3006.0-100052.3.3.1
3006.0-159000.5.3.2
3006.0-150052.5.3.1
3006.0-2.9.3
3006.0-2.9.1
3006.0-80052.6.3.2
3006.0-90052.6.3.1
3006.0-1.67.1
3006.0-2.22.1
3006.0-2.71.1
3006.0-2.40.2
3006.0-150000.3.86.1
3006.0-3.84.1
3006.0-220402.3.15.3
3006.0-240402.3.15.3
3006.0-120002.3.17.1
3006.0-150002.5.9.1
3006.0-120002.5.9.1
3006.0-70002.5.9.1
3006.0-80002.5.9.1
3006.0-90002.5.9.1
3006.0-2.6.5
3006.0-2.6.2
3006.0-2.3.2
3006.0-2.3.1
3006.0-1.64.1
3006.0-2.37.1
3006.0-2.77.1
3006.0-2.68.1
3006.0-2.19.1
3006.0-150000.3.83.1
3006.0-3.81.1
3006.0-240402.3.12.1
3006.0-220402.3.12.1
3006.0-120002.3.14.2
3006.0-70002.5.6.1
3006.0-80002.5.6.1
3006.0-90002.5.6.1
3006.0-150002.5.6.1
3006.0-120002.5.6.1
3006.0-220402.3.9.4
3006.0-240402.3.9.7
3006.0-120002.3.11.3
3006.0-150002.5.3.3
3006.0-120002.5.3.5
3006.0-70002.5.3.3
3006.0-80002.5.3.15
3006.0-90002.5.3.9
3006.0-3.6.2
3006.0-3.6.3
3006.0-3.8.4
3006.0-3.3.7
3006.0-3.3.5
3006.0-3.5.3
3006.0-1.53.2
3006.0-2.29.2
3006.0-2.69.2
3006.0-2.60.2
3006.0-2.11.1
3006.0-150000.3.75.5
3006.0-3.73.1
3006.0-1.50.1
3006.0-2.26.1
3006.0-2.57.2
3006.0-2.66.1
3006.0-150000.3.72.1
3006.0-3.68.1
3006.0-1.47.1
3006.0-2.23.1
3006.0-2.61.1
3006.0-2.54.3
3006.0-2.63.3
3006.0-150000.3.67.1
3006.0-3.65.1
3006.0-1.44.1
3006.0-2.20.1
3006.0-2.58.1
3006.0-2.51.1
3006.0-2.60.1
3006.0-150000.3.62.2
3006.0-3.60.3
3006.0-1.41.1
3006.0-2.17.1
3006.0-2.55.1
3006.0-2.48.1
3006.0-2.57.1
3006.0-150000.3.59.1
3006.0-3.57.1
3006.0-1.36.3
3006.0-2.12.3
3006.0-2.50.4
3006.0-2.43.3
3006.0-2.52.3
3006.0-150000.3.54.3
3006.0-3.52.3
3006.0-3.46.2
3006.0-150000.3.48.2
3006.0-2.46.4
3006.0-2.44.4
3006.0-2.6.3
3006.0-1.30.3
3006.0-2.40.1
3006.0-3.40.1
3006.0-150000.3.42.1
3006.0-2.38.1
3006.0-1.24.1
3006.0-3.33.2
3006.0-2.33.1
3006.0-1.19.2
3006.0-150000.3.35.1
3004-2.9.2
3004-3.9.1
3004-2.9.1
3004-159000.3.9.1
3004-3.11.1
3004-150000.3.11.1
3004-2.11.2
Vulnerabilities (54)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU86611 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-22231 |
CWE-22 | Low | 3006.0-1.36.3, 3006.0-2.12.3, 3006.0-2.43.3, 3006.0-2.50.4, 3006.0-2.52.3, 3006.0-3.52.3, 3006.0-150000.3.54.3 | 20.02.2024 |
SB2024022022 SB2024022023 SB2024022024 and 13 more |
||
| #VU82944 - UNIX Symbolic Link (Symlink) Following CVE-2023-34049 |
CWE-61 | Low | 3006.0-1.30.3, 3006.0-2.6.3, 3006.0-2.44.4, 3006.0-2.46.4, 3006.0-3.46.2, 3006.0-150000.3.48.2 | 09.11.2023 |
SB2023110931 SB2023110932 SB2023110933 and 17 more |
||
| #VU82817 - Incorrect Permission Assignment for Critical Resource CVE-2022-22941 |
CWE-732 | Medium | 3004-2.9.1, 3004-2.9.2, 3004-2.11.2, 3004-3.9.1, 3004-159000.3.9.1 | 07.11.2023 |
SB2022032942 SB2023110714 SB2022033035 and 21 more |
||
| #VU82815 - Authentication Bypass by Capture-replay CVE-2022-22936 |
CWE-294 | Medium | 3004-2.9.1, 3004-2.9.2, 3004-2.11.2, 3004-3.9.1, 3004-159000.3.9.1 | 07.11.2023 |
SB2022032942 SB2023110714 SB2022033035 and 21 more |
||
| #VU82801 - Insufficient Verification of Data Authenticity CVE-2022-22935 |
CWE-345 | Medium | 3004-2.9.1, 3004-2.9.2, 3004-2.11.2, 3004-3.9.1, 3004-159000.3.9.1 | 07.11.2023 |
SB2022032942 SB2023110714 SB2022033035 and 20 more |
||
| #VU82800 - Cryptographic Issues CVE-2022-22934 |
CWE-310 | Low | 3004-2.9.1, 3004-2.9.2, 3004-2.11.2, 3004-3.9.1, 3004-159000.3.9.1 | 07.11.2023 |
SB2022032942 SB2023110714 SB2022033035 and 21 more |
||
| #VU80472 - Permissions, Privileges, and Access Controls CVE-2023-20898 |
CWE-264 | Low | 3006.0-1.24.1, 3006.0-2.38.1, 3006.0-2.40.1, 3006.0-3.40.1, 3006.0-150000.3.42.1 | 05.09.2023 |
SB2023090559 SB2023090563 SB2023090601 and 13 more |
||
| #VU80471 - Improper input validation CVE-2023-20897 |
CWE-20 | Medium | 3006.0-1.24.1, 3006.0-2.38.1, 3006.0-2.40.1, 3006.0-3.40.1, 3006.0-150000.3.42.1 | 05.09.2023 |
SB2023090559 SB2023090563 SB2023090601 and 14 more |
||
| #VU76397 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2023-28370 |
CWE-601 | Medium | 3006.0-1.19.2, 3006.0-2.33.1, 3006.0-3.33.2, 3006.0-150000.3.35.1 | 22.05.2023 |
SB2023052204 SB2023061333 SB2023062257 and 28 more |
||
| #VU64660 - Improper Authentication CVE-2022-22967 |
CWE-287 | Low | 3004-2.11.2, 3004-3.11.1, 3004-150000.3.11.1 | 24.06.2022 |
SB2022062428 SB2022062430 SB2022062441 and 13 more |
||
| #VU61662 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2022-24302 |
CWE-362 | Low | 3004-3.9.1 | 28.03.2022 |
SB2022032832 SB2022032837 SB2022033014 and 20 more |
||
| #VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-0778 |
CWE-835 | Medium | 3004-3.9.1 | 15.03.2022 |
SB2022031520 SB2022031522 SB2022031611 and 238 more |
||
| #VU51777 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-28957 |
CWE-79 | Low | 3004-3.9.1 | 30.03.2021 |
SB2021033001 SB2021033005 SB2021040175 and 20 more |
||
| #VU16583 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2018-19787 |
CWE-79 | Low | 3004-3.9.1 | 17.12.2018 |
SB2018121812 SB2022031730 SB2024051024 and 4 more |
Showing elements 41 - 60 out of 54