Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 925021 (CVE-2024-22231, CVE-2024-22232) - <app-admin/salt-{3005.5,3006.6}: multiple vulnerabilities
Summary: <app-admin/salt-{3005.5,3006.6}: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2024-22231, CVE-2024-22232
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://saltproject.io/security-annou...
Whiteboard: B4 [glsa+]
Keywords:
Depends on:
Blocks:
 
Reported: 2024-02-19 23:40 UTC by John Helmert III
Modified: 2024-12-07 11:26 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2024-02-19 23:40:11 UTC
"CVE-2024-22231

    Description: Syndic cache directory creation is vulnerable to a directory traversal attack.
    Impact: An arbitrary directory can be created on a Salt master.
"

"CVE-2024-22232

    Description: A specially crafted url can be created which leads to a directory traversal in the salt file server.
    Impact: An arbitrary file can be read from a Salt master’s filesystem."

Please cleanup <3005.5 and <3006.6.
Comment 1 Larry the Git Cow gentoo-dev 2024-12-07 11:26:01 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=287c89a2f81a4c96109fce9a1d9172223043bd55

commit 287c89a2f81a4c96109fce9a1d9172223043bd55
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-12-07 11:25:36 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-12-07 11:25:59 +0000

    [ GLSA 202412-09 ] Salt: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/916512
    Bug: https://bugs.gentoo.org/925021
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202412-09.xml | 47 +++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 47 insertions(+)