© 2025-2026 PySpect
First version without a known vulnerability: 3006.17
Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
Fixed in: 3006.17
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
Fixed in: 3006.17, 3007.9
Salt vulnerable to directory traversal attack in file receiving method
Fixed in: 3007.4, 3006.12
Salt's worker process vulnerable to denial of service through file read operation
Fixed in: 3007.4, 3006.12
Salt's salt.auth.pki module does not properly authenticate callers
Fixed in: 3006.12, 3007.4
Salt's file contents overwrite the VirtKey class
Fixed in: 3007.4, 3006.12
Salt vulnerable to arbitrary event injection
Fixed in: 3006.12, 3007.4
Salt's on demand pillar functionality vulnerable to arbitrary command injections
Fixed in: 3006.12, 3007.4
Salt has minion event bus authorization bypass vulnerability
Fixed in: 3007.4, 3006.12
Salt vulnerable to directory traversal attack in minion file cache creation
Fixed in: 3006.12, 3007.4
Salt allows arbitrary directory creation or file deletion
Fixed in: 3007.4, 3006.12
Salt preflight script could be attacker controlled
Fixed in: 3005.4, 3006.4
Path traversal in saltstack
Fixed in: 3005.5, 3006.6
Directory creation by malicious user in saltstack
Fixed in: 3005.5, 3006.6
Salt can cause Git Providers to get wrong data
Fixed in: 3005.2, 3006.2
Salt vulnerable to denial of service
Fixed in: 3005.2, 3006.2
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file.
Fixed in: 3003.1
Salt's PAM auth fails to reject locked accounts
Fixed in: 3002.9, 3003.5, 3004.2
Improper Authentication in SaltStack Salt
Fixed in: 3003.3
Command Injection in SaltStack Salt
Fixed in: 3003rc1
Saltstack Salt Unauthenticated Arbitrary Code Execution
Fixed in: 3002.2
SaltStack Salt is vulnerable to shell injection via ProxyCommand argument
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.3, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt command injection in the Salt-API when using the Salt-SSH client
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.3, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt eauth tokens can be used once after expiration
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 3000.7, 3001.5, 3002.3, 2019.2.8, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt Directory Traversal vulnerability
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.3, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt Cleartext Storage of Sensitive Information via cmdmod
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.3, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt Server Side Template Injection
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.5, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4
SaltStack Salt Improper Authentication vulnerability
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.3, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt command injection via a crafted process name
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.3, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt Improper SSL Certificate Validation
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.3, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt Improper Certificate Validation
Fixed in: 2015.8.13, 2016.11.5, 2016.11.10, 2017.7.8, 2019.2.8, 3000.7, 3001.5, 3002.3, 2015.8.10, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2019.2.0rc1, 2019.2.5, 3000.6, 3001.4, 3002.5
SaltStack Salt Improper Validation of eauth credentials and tokens in salt-netapi
Fixed in: 2015.8.13, 2016.3.8, 2016.11.10, 2017.7.8, 2018.3.5, 2019.2.7, 3000.5, 3001.3, 3002.1, 2015.8.10, 2016.3.4, 2016.3.6, 2016.11.3, 2016.11.6, 2017.7.4, 2019.2.5, 3000.3
SaltStack Salt Command Injection in netapi ssh client
Fixed in: 2015.8.13, 2016.3.8, 2016.11.10, 2017.7.8, 2018.3.5, 2019.2.6, 3000.4, 3001.2, 3002.1, 2015.8.10, 2016.3.4, 2016.3.6, 2016.11.3, 2016.11.6, 2017.7.4, 2019.2.5, 3000.3
SaltStack Salt Allows creating certificates with weak file permissions
Fixed in: 2015.8.13, 2016.3.8, 2016.11.10, 2017.7.8, 2018.3.5, 2019.2.6, 3000.4, 3001.2, 3002.1, 2015.8.10, 2016.3.4, 2016.3.6, 2016.11.3, 2016.11.6, 2017.7.4, 2019.2.5, 3000.3
SaltStack Salt Unauthenticated Remote Code Execution
Fixed in: 2019.2.4, 3000.2
SaltStack Salt is vulnerable Arbitrary Directory Access
Fixed in: 2019.2.4, 3000.2
SaltStack Salt is vulnerable to command injection
Fixed in: 2019.2.3, 2019.2.1
SaltStack Salt SQL Injection vulnerability in mysql.user_chpass function
Fixed in: 2018.3.4
SaltStack Privilege Escalation vulnerability
Fixed in: 0.17.1
Minion identity not validated in saltstack
Fixed in: 0.17.1
SaltStack MITM SSH attack in salt-ssh
Fixed in: 0.17.1
SaltStack insecurely uses /tmp
Fixed in: 0.17.1
Salt has insufficient argument validation in several modules
Fixed in: 0.17.1
Salt Insecure configuration of PAM external authentication service
Fixed in: 2015.5.10, 2015.8.8
Salt allows deleted minions to read or write to minions with the same id
Fixed in: 2015.8.11
Salt uses weak permissions on the cache data
Fixed in: 2015.8.3
SaltStack has insecure /tmp file handling in salt/modules/chef.py
Fixed in: 2014.7.4, b49d0d4b5ca5c6f31f03e2caf97cef1088eeed81, 22d2f7a1ec93300c34e8c42d14ec39d51e610b5c
Salt improper handling of tmp files
Fixed in: 2014.7.4, e11298d7155e9982749483ca5538e46090caef9c
SaltStack Salt Information Exposure
Fixed in: 2016.11.4
salt password information leaked in debug logs
Fixed in: 2015.5.6, 2015.8.1, c0689e32154c41f59840ae10ffc5fbfa30618710
SaltStack Salt Insecure Temporary File Creation
Fixed in: 2014.1.10
SaltStack Salt Directory traversal vulnerability in minion id validation
Fixed in: 2016.11.7, 2017.7.1
SaltStack Salt Authentication Bypass when using the local_batch client from salt-api
Fixed in: 2015.8.13, 2016.3.5, 2016.11.2
salt leaks git usernames and passwords to the log
Fixed in: 2015.5.5, 28aa9b105804ff433d8f663b2f9b804f2b75495a
SaltStack Salt Directory traversal vulnerability in minion id validation
Fixed in: 2016.3.8, 2016.11.8, 2017.7.2, 80d90307b07b3703428ecbb7c8bb468e28a9ae6d
SaltStack Salt Denial of Service via a crafted authentication request
Fixed in: 2016.3.8, 2016.11.8, 2017.7.2, 5f8b5e1a0f23fe0f2be5b3c3e04199b57a53db5b
Salt vulnerable to Improper Certificate Validation
Fixed in: 2014.7.6
Salt Improper Access Control
Fixed in: 2015.8.4
SaltStack Salt allows compromised salt-minions to impersonate the salt-master
Fixed in: 2016.3.6
SaltStack Salt arbitrary command execution in Salt-api via ssh_client
Fixed in: 2015.8.13, 2016.3.5, 2016.11.2
SaltStack Salt Directory Traversal vulnerability in salt-api
Fixed in: 2017.7.8, 2018.3.3, 2016.11.10
SaltStack Salt Remote command execution and incorrect access control when using salt-api
Fixed in: 2017.7.8, 2018.3.3, 2016.11.10
SaltStack RSA Key Generation allows remote users to decrypt communications
Fixed in: 0.15.1
SaltStack Improper Verification of Cryptographic Signature
Fixed in: 3002.8, 3004.1, 3003.4
SaltStack Salt Authentication Bypass by Capture-replay
Fixed in: 3002.8, 3003.4, 3004.1
SaltStack Salt Improper Authentication via Man in the Middle Attack
Fixed in: 3002.8, 3003.4, 3004.1
SaltStack Salt Permissions Bypass
Fixed in: 3002.8, 3003.4, 3004.1
Exposure of Resource to Wrong Sphere in salt
Fixed in: 3003.3
Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.
Fixed in: 0.17.1