Junglewise Threat Intelligence

CVE-2020-11652: PYSEC-2020-103 - An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to

CVE-2020-11652 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-04-30

Technologies: Saltstack Salt. Vendors: PyPI, Saltstack.

Executive brief

The salt-master process ClearFuncs class in SaltStack Salt contains a path traversal vulnerability due to improper sanitization of paths in certain methods. This allows authenticated users to gain arbitrary directory access on the master server.

Affected products

  • SaltStack Salt before 2019.2.4, 3000 before 3000.2

Timeline

  • 2020-04-30: patched: Salt 2019.2.4 and 3000.2 released to address the issue.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed

Related threats