GHSA-q27c-j6j9-53w3
GitHub Security Advisory
Directory creation by malicious user in saltstack
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.
Affected Packages
PyPI
salt
Affected versions:
0
(fixed in 3005.5)
PyPI
salt
Affected versions:
3006.0
(fixed in 3006.6)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 19, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.