CVE-2024-22232: VMware Salt Project

High severity, CVSS 7.7. EPSS: 0.8% chance of exploitation in the next 30 days.

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.

Affected products

Published 2024-06-27. Last modified 2026-06-17.