GHSA-989c-m532-p2hv

Suggest an improvement
Source
https://github.com/advisories/GHSA-989c-m532-p2hv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-989c-m532-p2hv/GHSA-989c-m532-p2hv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-989c-m532-p2hv
Aliases
Published
2025-06-13T09:30:34Z
Modified
2026-07-07T17:56:28Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:H CVSS Calculator
Summary
Salt's worker process vulnerable to denial of service through file read operation
Details

Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method which is exposed to all minions. The un-sanitized input value “jid” is used to construct a path which is then opened for reading. An attacker could exploit this vulnerabilities by attempting to read from a filename that will not return any data, e.g. by targeting a pipe node on the proc file system.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-06-13T21:57:41Z",
    "nvd_published_at": "2025-06-13T07:15:21Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / salt

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3007.0rc1
Fixed
3007.4

Affected versions

3007.*
3007.0rc1
3007.0
3007.1
3007.2
3007.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-989c-m532-p2hv/GHSA-989c-m532-p2hv.json"

PyPI / salt

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3006.0rc1
Fixed
3006.12

Affected versions

3006.*
3006.0rc1
3006.0rc2
3006.0rc3
3006.0
3006.1
3006.2
3006.3
3006.4
3006.5
3006.6
3006.7
3006.8
3006.9
3006.10
3006.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-989c-m532-p2hv/GHSA-989c-m532-p2hv.json"