Products
Salt
Source
security@vmware.com
Tags
CVE-2024-22231 details
Published : June 27, 2024, 7:15 a.m.
Last Modified : June 27, 2024, 12:47 p.m.
Last Modified : June 27, 2024, 12:47 p.m.
Description
Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.
CVSS Score
1 | 2 | 3 | 4 | 5.0 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Base Score
5.0
Exploitability Score
3.1
Impact Score
1.4
Base Severity
MEDIUM
Vector String : CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
References
URL | Source |
---|---|
https://saltproject.io/security-announcements/2024-01-31-advisory/ | security@vmware.com |
This website uses the NVD API, but is not approved or certified by it.