Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.2 PyPI

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

GHSA-vcf3-26xf-fw4m · CVE-2025-62349

Published · Modified

Description

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

Ready to move

Start Securing

Free, no credit card | First findings in minutes