ALT-PU-2024-2790-1

Обновление пакета salt в ветке sisyphus_loongarch64

Версия3006.6-alt1
Задание#0
Опубликовано2024-02-21
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (2)

CVE-2024-22231
MEDIUM5.0

Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.

Опубликовано: 2024-06-27Изменено: 2026-04-15
CVSS 3.xСРЕДНЯЯ 5.0
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
CVE-2024-22232
HIGH7.7

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.

Опубликовано: 2024-06-27Изменено: 2026-04-15
CVSS 3.xВЫСОКАЯ 7.7
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N