CVE-2024-22232 describes a directory traversal vulnerability in the Salt file server, allowing an authenticated attacker to read arbitrary files from the Salt master's filesystem by crafting a malicious URL. This high-severity vulnerability (CVSS 7.7) has a low attack complexity and requires low privileges, posing a significant risk of sensitive data exposure. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using Salt should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| VMware | Salt Project | >= 0, < 3005.5, 3006.6CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.