CVE-2023-20897: SaltStack Salt
Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to the number of worker threads, the master will become unresponsive to return requests until restarted.
Affected products
- SaltStack Salt: before 3005.2 (fixed in 3005.2); from 3006.0, before 3006.2 (fixed in 3006.2)
Published 2023-09-05. Last modified 2026-06-17.