Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 925021 (CVE-2024-22231, CVE-2024-22232)

Summary: <app-admin/salt-{3005.5,3006.6}: multiple vulnerabilities
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: CONFIRMED ---    
Severity: minor CC: chutzpah
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://saltproject.io/security-announcements/2024-01-31-advisory/
Whiteboard: B4 [glsa?]
Package list:
Runtime testing required: ---

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2024-02-19 23:40:11 UTC
"CVE-2024-22231

    Description: Syndic cache directory creation is vulnerable to a directory traversal attack.
    Impact: An arbitrary directory can be created on a Salt master.
"

"CVE-2024-22232

    Description: A specially crafted url can be created which leads to a directory traversal in the salt file server.
    Impact: An arbitrary file can be read from a Salt master’s filesystem."

Please cleanup <3005.5 and <3006.6.