CVE-2025-22238: Salt vulnerable to directory traversal attack in minion file cache creation
Directory traversal attack in minion file cache creation. The master’s default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite ‘cache’ files outside of the cache directory.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-22238 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →