Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yudi Zhao

Researcher fromHuawei Nebula Security Lab
#20261of 53,639
12.7Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2024-4384
5.0
2024-01-31
Salt · Salt · CVE-2024-22231
**Name of the Vulnerable Software and Affected Versions** Salt (affected versions not specified) **Description** The issue is related to a directory traversal attack in the Salt project, specifically in the Syndic cache directory creation. This could allow a malicious attacker to create an arbitrary directory on a Salt master. The vulnerability may also be exploited to execute arbitrary code remotely. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-4385
7.7
2024-01-31
Salt · Salt · CVE-2024-22232
**Name of the Vulnerable Software and Affected Versions** Salt (affected versions not specified) **Description** The issue is related to the creation of specially crafted URLs, leading to directory traversal on the Salt file server. This can allow a malicious user to read arbitrary files from a Salt master's filesystem. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.