Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.2 PyPI

Salt vulnerable to directory traversal attack in minion file cache creation

GHSA-r546-h3ff-q585 · CVE-2025-22238

Published · Modified

Description

Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.

Ready to move

Start Securing

Free, no credit card | First findings in minutes