Skip to main content

Exposure of Sensitive Information to an Unauthorized Actor

CVE-2023-20898

Severity High
Score 7.8/10

Summary

Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters versions prior to 3005.2, and 3006.x prior to 3006.2. Anything that uses Git Providers with different environments can get garbage data or the wrong data, which can lead to wrongful data disclosure, wrongful executions, data corruption, and/or crash.

  • HIGH
  • LOCAL
  • HIGH
  • CHANGED
  • NONE
  • LOW
  • HIGH
  • HIGH

CWE-200 - Information Exposure

An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.

Advisory Timeline

  • Published