CVE-2024-22232: VMware Salt Project
High severity, CVSS 7.7. EPSS: 0.8% chance of exploitation in the next 30 days.
A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
Affected products
- VMware Salt Project
Published 2024-06-27. Last modified 2026-06-17.