High severityCISA KEVNVD Advisory· Published Apr 30, 2020· Updated Oct 21, 2025
CVE-2020-11652
CVE-2020-11652
Description
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
saltPyPI | < 2019.2.4 | 2019.2.4 |
saltPyPI | >= 3000, < 3000.2 | 3000.2 |
Affected products
1- SaltStack/Saltdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.htmlghsavendor-advisoryx_refsource_SUSEWEB
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.htmlghsavendor-advisoryx_refsource_SUSEWEB
- github.com/advisories/GHSA-vp49-2g4r-m3x3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-11652ghsaADVISORY
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AGghsavendor-advisoryx_refsource_CISCOWEB
- usn.ubuntu.com/4459-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2020/dsa-4676ghsavendor-advisoryx_refsource_DEBIANWEB
- packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.htmlghsax_refsource_MISCWEB
- packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.htmlghsax_refsource_MISCWEB
- support.blackberry.com/kb/articleDetailghsax_refsource_MISCWEB
- www.vmware.com/security/advisories/VMSA-2020-0009.htmlghsax_refsource_CONFIRMWEB
- docs.saltstack.com/en/latest/topics/releases/2019.2.4.htmlghsax_refsource_MISCWEB
- github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2020-103.yamlghsaWEB
- github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rstghsax_refsource_MISCWEB
- lists.debian.org/debian-lts-announce/2020/05/msg00027.htmlghsamailing-listx_refsource_MLISTWEB
- usn.ubuntu.com/4459-1ghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalogghsaWEB
News mentions
0No linked articles in our index yet.