SaltStack 3000 < 3006.12 / 3007 < 3007.4 Multiple Vulnerabilities

critical Nessus Plugin ID 240180

Synopsis

The version of SaltStack running on the remote server is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the instance of SaltStack hosted on the remote server is affected by multiple vulnerabilities, including the following:

- Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory. (CVE-2024-38824)

- Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0). (CVE-2025-22236)

- Arbitrary event injection on Salt Master. The master's _minion_event method can be used by and authorized minion to send arbitrary events onto the master's event bus. (CVE-2025-22239)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version

Solution

Upgrade to SaltStack version referenced in the vendor security advisory.

See Also

http://www.nessus.org/u?f8eb1393

Plugin Details

Severity: Critical

ID: 240180

File Name: saltstack_3007_4.nasl

Version: 1.1

Type: local

Agent: unix

Family: Misc.

Published: 6/19/2025

Updated: 6/19/2025

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.2

CVSS v2

Risk Factor: High

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-38824

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Vulnerability Information

CPE: cpe:/a:saltstack:salt

Required KB Items: installed_sw/SaltStack Salt Master

Patch Publication Date: 5/12/2025

Vulnerability Publication Date: 5/12/2025

Reference Information

CVE: CVE-2024-38822, CVE-2024-38823, CVE-2024-38824, CVE-2024-38825, CVE-2025-22236, CVE-2025-22237, CVE-2025-22238, CVE-2025-22239, CVE-2025-22240, CVE-2025-22241, CVE-2025-22242, CVE-2025-29087