VYPR
High severityCISA KEVNVD Advisory· Published Apr 30, 2020· Updated Oct 21, 2025

CVE-2020-11652

CVE-2020-11652

Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
saltPyPI
< 2019.2.42019.2.4
saltPyPI
>= 3000, < 3000.23000.2

Affected products

1
  • SaltStack/Saltdescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.