{"schema_version":"1.9.0","id":"CVE-2024-38824","published":"2025-06-13T07:10:31.166Z","modified":"2026-08-12T03:51:22.661285431Z","aliases":["GHSA-8pcp-r83j-fc92","PYSEC-2026-529"],"related":["SUSE-EL-9-CLIENT-TOOLS-2025-2499","SUSE-SU-2025:02476-1","SUSE-SU-2025:02491-1","SUSE-SU-2025:02492-1","SUSE-SU-2025:02499-1","SUSE-SU-2025:02500-1","SUSE-SU-2025:02501-1","SUSE-SU-2025:02502-1","SUSE-SU-2025:02534-1","SUSE-SU-2025:20487-1","SUSE-SU-2025:20504-1","openSUSE-SU-2025:15295-1"],"summary":"CVE-2024-38824 salt advisory","details":"Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/saltstack/salt","events":[{"introduced":"86bb64dde27281d545ef46e1a42471a90c494197"},{"fixed":"1245edf4005768674f1e893cd3939de66bb8a731"},{"introduced":"31c9d0df191009207c72ea73abfd3a1e3a0e6425"},{"fixed":"619f4e26e71b3cbef89c115f37a2a976eb567264"}],"database_specific":{"cpe":"cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3006.0"},{"fixed":"3006.12"},{"introduced":"3007.0"},{"fixed":"3007.4"}],"source":"CPE_RANGE"}}],"versions":["v3007.3","v3006.11","v3007.2","v3006.10","v3006.9","v3007.1","v3006.8","v3007.0","v3006.7","v3006.5","v3006.3","v3006.3_docs","v3006.1","v3006.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38824.json"}}],"references":[{"type":"WEB","url":"https://docs.saltproject.io/en/3006/topics/releases/3006.12.html"},{"type":"WEB","url":"https://docs.saltproject.io/en/3007/topics/releases/3007.4.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38824.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38824"}],"database_specific":{"cna_assigner":"vmware","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38824.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3006.x"},{"fixed":"3006.12"},{"introduced":"3007.x"},{"fixed":"3007.4"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}