CVE-2020-11652
MEDIUM KEVSalt < 2019.2.4 - Path Traversal
Title source: ruleDescription
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Exploits (10)
exploitdb
WORKING POC
by Jasper Lievisse Adriaanse · textremotemultiple
https://www.exploit-db.com/exploits/48421
vulncheck_xdb
SCANNER
remote
https://github.com/appcheck-ng/salt-rce-scanner-CVE-2020-11651-CVE-2020-11652
metasploit
WORKING POC
by F-Secure, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/saltstack_salt_root_key.rb
metasploit
WORKING POC
GREAT
by F-Secure, wvu · rubypocpython
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/saltstack_salt_unauth_rce.rb
References (13)
Scores
CVSS v3
6.5
EPSS
0.9388
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CISA KEV
2021-11-03
VulnCheck KEV
2020-07-22
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2020-0172
CWE
CWE-22
Status
published
Products (12)
blackberry/workspaces_server
9.1.0
blackberry/workspaces_server
< 7.1.3
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
18.04
debian/debian_linux
8.0
debian/debian_linux
9.0
debian/debian_linux
10.0
opensuse/leap
15.1
pypi/salt
0 - 2019.2.4PyPI
saltstack/salt
< 2019.2.4
... and 2 more
Published
Apr 30, 2020
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026