GHSA-8pcp-r83j-fc92
GitHub Security Advisory
Salt vulnerable to directory traversal attack in file receiving method
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.
Affected Packages
PyPI
salt
Affected versions:
3007.0rc1
(fixed in 3007.4)
PyPI
salt
Affected versions:
3006.0rc1
(fixed in 3006.12)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.