-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| salt | pip | < 3002.2 | 3002.2 |
The vulnerability stems from improper authentication in Salt's components, allowing local attackers to execute code without credentials. While the exact code diff isn't available, the CWE-303 (incorrect auth algorithm) and CWE-287 (missing authentication) suggest flaws in core authentication functions. The Auth class initialization and message handling in the transport layer are critical points where improper credential validation() could occur. The confidence is medium due to lack of direct code references, but these components are central to Salt's authentication workflow.
Ongoing coverage of React2Shell