Junglewise Threat Intelligence

CVE-2020-11651: PYSEC-2020-102 - An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly

CVE-2020-11651 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-04-30

Technologies: salt (PyPI), Saltstack Salt. Vendors: PyPI, Saltstack.

Executive brief

The salt-master process ClearFuncs class in SaltStack Salt fails to properly validate method calls, leading to an authentication bypass. Remote unauthenticated attackers can exploit this to retrieve user tokens from the master or execute arbitrary commands on salt minions.

Affected products

  • SaltStack Salt before 2019.2.4, 3000 before 3000.2

Timeline

  • 2020-04-30: patched: Salt versions 2019.2.4 and 3000.2 released to address the vulnerability.
  • 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: NVD publication date.

Related threats