Description
Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 1.2 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: High
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: Low
Availability: None
Affected Packages1 packages
🔴Vulnerability Details
3CVEListCVE-2024-38823 Salt Advisory↗2025-06-13 ▶ GHSAGHSA-85cw-m46v-23x6: Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport↗2025-06-13 ▶ OSVCVE-2024-38823: Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport↗2025-06-13 ▶