GHSA-c46w-gr7f-jm2p
GitHub Security Advisory
Salt vulnerable to arbitrary event injection
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.
Affected Packages
PyPI
salt
Affected versions:
3006.0rc1
(fixed in 3006.12)
PyPI
salt
Affected versions:
3007.0rc1
(fixed in 3007.4)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 14, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.