CVE-2023-20898

5 documents4 sources
Severity
7.8HIGH
EPSS
0.1%
top 74.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 5

Description

Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 3006.2. Anything that uses Git Providers with different environments can get garbage data or the wrong data, which can lead to wrongful data disclosure, wrongful executions, data corruption and/or crash.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:NExploitability: 1.1 | Impact: 2.7

Affected Packages3 packages

PyPIsalt3006.0rc13006.2+2
NVDsaltstack/salt3006.03006.2+1
CVEListV5saltSalt masters prior to 3005.2 or 3006.2

🔴Vulnerability Details

4
OSV
Salt can cause Git Providers to get wrong data2023-09-05
GHSA
Salt can cause Git Providers to get wrong data2023-09-05
OSV
CVE-2023-20898: Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 30052023-09-05
CVEList
CVE-2023-20898: Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 30052023-09-05