Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20898


Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that uses Git Providers with different environments can get garbage data or the wrong data, which can lead to wrongful data disclosure, wrongful executions, data corruption and/or crash.


Published

2023-09-05T11:15:33.300

Last Modified

2025-02-13T17:16:02.527

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.2 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application saltstack salt < 3005.2 Yes
Application saltstack salt < 3006.2 Yes

References