Vulnerability Description
Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://docs.saltproject.io/en/3006/topics/releases/3006.12.html
- https://docs.saltproject.io/en/3007/topics/releases/3007.4.html
FAQ
What is CVE-2025-22238?
CVE-2025-22238 is a vulnerability with a CVSS score of 4.2 (MEDIUM). Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside...
How severe is CVE-2025-22238?
CVE-2025-22238 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-22238?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.