100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether salt is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
PyPI

CVE-2017-12791

CVE-2017-12791

CRITICAL 9.8
PyPI

CVE-2017-12791

SaltStack Salt Directory traversal vulnerability in minion id validation

CRITICAL 9.8
PyPI

CVE-2017-12791

CVE-2017-12791

MEDIUM 5.6
PyPI

CVE-2025-22241

Salt's file contents overwrite the VirtKey class

MEDIUM 6.7
PyPI

CVE-2023-34049

Salt preflight script could be attacker controlled

MEDIUM 6.7
PyPI

CVE-2025-22237

Salt's on demand pillar functionality vulnerable to arbitrary command injections

HIGH 8.1
PyPI

CVE-2025-22239

Salt vulnerable to arbitrary event injection

MEDIUM 6.3
PyPI

CVE-2025-22240

Salt allows arbitrary directory creation or file deletion

HIGH 7.7
PyPI

CVE-2024-22232

Path traversal in saltstack

MEDIUM 4.2
PyPI

CVE-2025-22238

Salt vulnerable to directory traversal attack in minion file cache creation

HIGH 7.8
PyPI

CVE-2025-62348

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

MEDIUM 5.0
PyPI

CVE-2024-22231

Directory creation by malicious user in saltstack

MEDIUM 5.6
PyPI

CVE-2025-22242

Salt's worker process vulnerable to denial of service through file read operation

HIGH 8.1
PyPI

CVE-2025-22236

Salt has minion event bus authorization bypass vulnerability

MEDIUM 6.4
PyPI

CVE-2024-38825

Salt's salt.auth.pki module does not properly authenticate callers

MEDIUM 6.2
PyPI

CVE-2025-62349

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

MEDIUM 6.3
PyPI

CVE-2025-22240

Salt allows arbitrary directory creation or file deletion

MEDIUM 6.2
PyPI

CVE-2025-62349

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

MEDIUM 5.0
PyPI

CVE-2024-22231

Directory creation by malicious user in saltstack

MEDIUM 4.2
PyPI

CVE-2025-22238

Salt vulnerable to directory traversal attack in minion file cache creation

MEDIUM 6.7
PyPI

CVE-2025-22237

Salt's on demand pillar functionality vulnerable to arbitrary command injections

HIGH 7.8
PyPI

CVE-2025-62348

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

HIGH 8.1
PyPI

CVE-2025-22239

Salt vulnerable to arbitrary event injection

HIGH 8.1
PyPI

CVE-2025-22236

Salt has minion event bus authorization bypass vulnerability

MEDIUM 5.6
PyPI

CVE-2025-22242

Salt's worker process vulnerable to denial of service through file read operation

MEDIUM 5.6
PyPI

CVE-2025-22241

Salt's file contents overwrite the VirtKey class

MEDIUM 6.7
PyPI

CVE-2023-34049

Salt preflight script could be attacker controlled

MEDIUM 6.4
PyPI

CVE-2024-38825

Salt's salt.auth.pki module does not properly authenticate callers

HIGH 7.7
PyPI

CVE-2024-22232

Path traversal in saltstack

HIGH 8.1
PyPI

CVE-2013-2228

SaltStack RSA Key Generation allows remote users to decrypt communications

HIGH 8.1
PyPI

CVE-2013-2228

SaltStack RSA Key Generation allows remote users to decrypt communications

CRITICAL 9.6
PyPI

CVE-2024-38824

Salt vulnerable to directory traversal attack in file receiving method

CRITICAL 9.6
PyPI

CVE-2024-38824

Salt vulnerable to directory traversal attack in file receiving method

UNKNOWN
PyPI

CVE-2015-6941

CVE-2015-6941

UNKNOWN
PyPI

CVE-2017-14696

CVE-2017-14696

UNKNOWN
PyPI

CVE-2017-14695

CVE-2017-14695

UNKNOWN
PyPI

CVE-2015-6918

CVE-2015-6918

UNKNOWN
PyPI

CVE-2015-1839

CVE-2015-1839

UNKNOWN
PyPI

CVE-2015-1838

CVE-2015-1838

HIGH 7.8
PyPI

CVE-2023-20898

CVE-2023-20898

UNKNOWN
PyPI

CVE-2022-22941

CVE-2022-22941

MEDIUM 5.3
PyPI

CVE-2023-20897

CVE-2023-20897

UNKNOWN
PyPI

CVE-2022-22936

CVE-2022-22936

UNKNOWN
PyPI

CVE-2022-22935

CVE-2022-22935

UNKNOWN
PyPI

CVE-2022-22934

CVE-2022-22934

UNKNOWN
PyPI

CVE-2020-28972

CVE-2020-28972

UNKNOWN
PyPI

CVE-2020-35662

CVE-2020-35662

HIGH 7.8
PyPI

CVE-2021-25315

CVE-2021-25315

UNKNOWN
PyPI

CVE-2020-28243

CVE-2020-28243

UNKNOWN
PyPI

CVE-2021-3197

CVE-2021-3197

UNKNOWN
PyPI

CVE-2021-3148

CVE-2021-3148

UNKNOWN
PyPI

CVE-2021-25283

CVE-2021-25283

UNKNOWN
PyPI

CVE-2021-3144

CVE-2021-3144

UNKNOWN
PyPI

CVE-2021-25284

CVE-2021-25284

UNKNOWN
PyPI

CVE-2021-25282

CVE-2021-25282

UNKNOWN
PyPI

CVE-2021-25281

CVE-2021-25281

UNKNOWN
PyPI

CVE-2019-17361

CVE-2019-17361

UNKNOWN
PyPI

CVE-2020-17490

CVE-2020-17490

UNKNOWN
PyPI

CVE-2020-25592

CVE-2020-25592

UNKNOWN
PyPI KEV

CVE-2020-16846

CVE-2020-16846

UNKNOWN
PyPI KEV

CVE-2020-11651

CVE-2020-11651

UNKNOWN
PyPI KEV

CVE-2020-11652

CVE-2020-11652

UNKNOWN
PyPI

CVE-2019-1010259

CVE-2019-1010259

UNKNOWN
PyPI

CVE-2018-15751

CVE-2018-15751

UNKNOWN
PyPI

CVE-2017-7893

CVE-2017-7893

UNKNOWN
PyPI

CVE-2018-15750

CVE-2018-15750

UNKNOWN
PyPI

CVE-2017-5200

CVE-2017-5200

UNKNOWN
PyPI

CVE-2017-5192

CVE-2017-5192

UNKNOWN
PyPI

CVE-2017-8109

CVE-2017-8109

UNKNOWN
PyPI

CVE-2015-4017

CVE-2015-4017

UNKNOWN
PyPI

CVE-2013-4435

CVE-2013-4435

UNKNOWN
PyPI

CVE-2016-3176

CVE-2016-3176

UNKNOWN
PyPI

CVE-2016-9639

CVE-2016-9639

UNKNOWN
PyPI

CVE-2015-8034

CVE-2015-8034

UNKNOWN
PyPI

CVE-2013-6617

CVE-2013-6617

UNKNOWN
PyPI

CVE-2016-1866

CVE-2016-1866

UNKNOWN
PyPI

CVE-2014-3563

CVE-2014-3563

UNKNOWN
PyPI

CVE-2013-4436

CVE-2013-4436

UNKNOWN
PyPI

CVE-2013-4437

CVE-2013-4437

CRITICAL 9.8
PyPI KEV

CVE-2020-16846

SaltStack Salt Command Injection in netapi ssh client

MEDIUM 6.5
PyPI KEV

CVE-2020-11652

SaltStack Salt is vulnerable Arbitrary Directory Access

HIGH 7.8
PyPI

CVE-2021-25315

Saltstack Salt Unauthenticated Arbitrary Code Execution

MEDIUM 5.3
PyPI

CVE-2023-20897

Salt vulnerable to denial of service

MEDIUM 4.2
PyPI

CVE-2023-20898

Salt can cause Git Providers to get wrong data

HIGH 7.5
PyPI

CVE-2013-6617

SaltStack Privilege Escalation vulnerability

MEDIUM 6.5
PyPI

CVE-2013-4439

Minion identity not validated in saltstack

CRITICAL 9.8
PyPI

CVE-2017-7893

SaltStack Salt allows compromised salt-minions to impersonate the salt-master

HIGH 8.8
PyPI

CVE-2017-5200

SaltStack Salt arbitrary command execution in Salt-api via ssh_client

MEDIUM 5.3
PyPI

CVE-2015-1838

Salt improper handling of tmp files

MEDIUM 5.3
PyPI

CVE-2015-1839

SaltStack has insecure /tmp file handling in salt/modules/chef.py

UNKNOWN
PyPI

CVE-2014-3563

SaltStack Salt Insecure Temporary File Creation

HIGH 7.5
PyPI

CVE-2022-22967

Salt's PAM auth fails to reject locked accounts

CRITICAL 9.1
PyPI

CVE-2021-25282

SaltStack Salt Directory Traversal vulnerability

CRITICAL 9.8
PyPI KEV

CVE-2020-11651

SaltStack Salt Unauthenticated Remote Code Execution

MEDIUM 6.4
PyPI

CVE-2021-22004

Improper Authentication in SaltStack Salt

HIGH 8.8
PyPI

CVE-2022-22934

SaltStack Improper Verification of Cryptographic Signature

MEDIUM 5.9
PyPI

CVE-2020-28972

SaltStack Salt Improper Certificate Validation

HIGH 8.8
PyPI

CVE-2013-4435

Salt has insufficient argument validation in several modules

HIGH 7.8
PyPI

CVE-2017-8109

SaltStack Salt Information Exposure

UNKNOWN
PyPI

CVE-2013-4437

SaltStack insecurely uses /tmp

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes