Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20897


Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.


Published

2023-09-05T11:15:32.973

Last Modified

2025-02-13T17:16:02.387

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-404

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application saltstack salt < 3005.2 Yes
Application saltstack salt < 3006.2 Yes

References