ATTENTION! Some critical vulnerabilities have been discovered in Salt versions 3004 and earlier

Dear Salt users and Salt Project Community members,

Some critical vulnerabilities have been discovered in Salt versions 3004 and earlier.

The vulnerabilities range in rating from Medium to High based on the Common Vulnerability Scoring System (CVSS). We are preparing a CVE release to be available on Monday, March 28th.

The CVE packages will be available for 3002.8, 3003.4, and 3004.1. The releases will only contain the fixes available to resolve and remediate the identified vulnerabilities. We advise all users to quickly apply the CVE release as soon as the packages are available. Please reach out if you have any questions or comments. You can reach us at saltproject-security.pdl@broadcom.com.

Thank you,

Your Salt Open Core team