CVE-2020-11652

MEDIUM KEV

Salt < 2019.2.4 - Path Traversal

Title source: rule

Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

Exploits (10)

exploitdb WORKING POC
by Jasper Lievisse Adriaanse · textremotemultiple
https://www.exploit-db.com/exploits/48421
nomisec WORKING POC 6 stars
by Al1ex · remote
https://github.com/Al1ex/CVE-2020-11652
nomisec WORKING POC 4 stars
by limon768 · remote
https://github.com/limon768/CVE-2020-11652-POC
nomisec WORKING POC
by fanjq99 · remote
https://github.com/fanjq99/CVE-2020-11652
vulncheck_xdb WORKING POC
remote
https://github.com/Drew-Alleman/CVE-2020-11651
vulncheck_xdb SCANNER
remote
https://github.com/appcheck-ng/salt-rce-scanner-CVE-2020-11651-CVE-2020-11652
vulncheck_xdb WORKING POC
remote
https://github.com/ssrsec/CVE-2020-11651-CVE-2020-11652-EXP
vulncheck_xdb WORKING POC
remote
https://github.com/jasperla/CVE-2020-11651-poc
metasploit WORKING POC
by F-Secure, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/saltstack_salt_root_key.rb
metasploit WORKING POC GREAT
by F-Secure, wvu · rubypocpython
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/saltstack_salt_unauth_rce.rb

Scores

CVSS v3 6.5
EPSS 0.9388
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-07-22
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2020-0172
CWE
CWE-22
Status published
Products (12)
blackberry/workspaces_server 9.1.0
blackberry/workspaces_server < 7.1.3
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
debian/debian_linux 8.0
debian/debian_linux 9.0
debian/debian_linux 10.0
opensuse/leap 15.1
pypi/salt 0 - 2019.2.4PyPI
saltstack/salt < 2019.2.4
... and 2 more
Published Apr 30, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026